Known Vulnerabilities for YouTrack by JetBrains
Listed below are 10 of the newest known vulnerabilities associated with "YouTrack" by "JetBrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75051 json | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75050 json | In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75049 json | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other proj... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75048 json | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75047 json | In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75046 json | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75045 json | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database ... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75044 json | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user ... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-62422 json | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-61492 json | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | Not Provided | 2026-07-10 | 2026-07-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Youtrack | 7.0.29566 | |||
| Application | Jetbrains | Youtrack | 7.0.28958 | |||
| Application | Jetbrains | Youtrack | 7.0.28450 | |||
| Application | Jetbrains | Youtrack | 7.0.28110 | |||
| Application | Jetbrains | Youtrack | 7.0.27965 | |||
| Application | Jetbrains | Youtrack | 7.0.27777 | |||
| Application | Jetbrains | Youtrack | 7.0.27705 | |||
| Application | Jetbrains | Youtrack | 7.0.27676 | |||
| Application | Jetbrains | Youtrack | 7.0.26927 | |||
| Application | Jetbrains | Youtrack | 7.0.26754 | |||
| Application | Jetbrains | Youtrack | 7.0.26630 | |||
| Application | Jetbrains | Youtrack | 7.0.26198 | |||
| Application | Jetbrains | Youtrack | 6.5.17122 | |||
| Application | Jetbrains | Youtrack | 6.5.17105 | |||
| Application | Jetbrains | Youtrack | 6.5.17057 | |||
| Application | Jetbrains | Youtrack | 6.5.17031 | |||
| Application | Jetbrains | Youtrack | 6.0.12634 | |||
| Application | Jetbrains | Youtrack | 6.0.12124 | |||
| Application | Jetbrains | Youtrack | 5.2.5 | |||
| Application | Jetbrains | Youtrack | 4.2.4 |