CVEs (269)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
In JetBrains TeamCity before 2026.1,
2025.11.5 reflected XSS was possible on the repository download page |
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible |
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible |
In JetBrains TeamCity before 2026.1
2025.11.5 authenticated users could expose server API to unauthorised access |
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk |
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations |
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow |
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token |
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test |