| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host |
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues |
| In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible |
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission |
| In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation |
| In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint |
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible |