← Back

Jetbrains

jetbrains

582 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Goland
goland
Webstorm
webstorm
Resharper
resharper
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (582)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Youtrack
Jul 10, 2026
Jul 10, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
1Jetbrains
1Teamcity
Jul 14, 2026
Jul 10, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
1Jetbrains
1Teamcity
Jul 13, 2026
Jul 10, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
1Jetbrains
1Teamcity
Jul 10, 2026
Jul 10, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
1Jetbrains
1Teamcity
Jul 14, 2026
Jul 10, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
1Jetbrains
1Intellij Idea
Jul 14, 2026
Jul 10, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
1Jetbrains
1Youtrack
Jul 10, 2026
Jul 10, 2026
N/A· v4
3.5 LOW· v3
N/A· v2
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
1Jetbrains
1Kotlin
Jun 27, 2026
Jun 26, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
1Jetbrains
1Hub
Jun 26, 2026
Jun 19, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
1Jetbrains
1Hub
Jun 26, 2026
Jun 19, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
1Jetbrains
1Goland
Jun 26, 2026
Jun 19, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
1Jetbrains
1Hub
Jun 26, 2026
Jun 19, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
1Jetbrains
1Youtrack
Jul 22, 2026
May 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
1Jetbrains
1Youtrack
Jul 22, 2026
May 29, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts