Vulnerabilities
Vulnerable Software
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
CVSS Score
7.1
EPSS Score
0.008
Published
2026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVSS Score
8.1
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVSS Score
9.1
EPSS Score
0.003
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
CVSS Score
6.5
EPSS Score
0.009
Published
2026-08-17
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVSS Score
8.2
EPSS Score
0.002
Published
2026-08-17
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
CVSS Score
6.5
EPSS Score
0.003
Published
2026-08-17


Contact Us

Shodan ® - All rights reserved