Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas |
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts |
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible |
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
In JetBrains TeamCity before 2026.1,
2025.11.5 reflected XSS was possible on the repository download page |
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible |
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible |
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests |
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages |
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible |
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account |