📦

youtrack

Vendor: jetbrains

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 5 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 0.85% Exploit Prob.
Latest CVE CVE-2026-62422 Jul 14

Security Vulnerability Index

Page 1 / 15
10.0 CVSS

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

EPSS: 0.33%
3.5 CVSS

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

EPSS: 0.66%
3.5 CVSS

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

EPSS: 0.23%
2.6 CVSS

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

EPSS: 0.34%
4.3 CVSS

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

EPSS: 0.27%
4.3 CVSS

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

EPSS: 0.27%
5.3 CVSS

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

EPSS: 0.27%
3.1 CVSS

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

EPSS: 0.24%
4.3 CVSS

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

EPSS: 0.30%
6.5 CVSS

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

EPSS: 0.26%