Skip to main content

Vendor archive

jetbrains CVEs

Beta · best-effort

601 CVEs tagged to vendor jetbrains50 Critical, 139 High, 347 Medium, 65 Low, 0 Unrated.

CVE-2025-57731

Published Aug 20, 2025

In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57730

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57729

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57728

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57727

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54538

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54537

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54536

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54535

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54534

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54533

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54532

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54531

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54530

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54529

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54528

Published Jul 28, 2025

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54527

Published Jul 28, 2025

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53959

Published Jul 15, 2025

In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52879

Published Jun 23, 2025

In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52878

Published Jun 23, 2025

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52877

Published Jun 23, 2025

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52876

Published Jun 23, 2025

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52875

Published Jun 23, 2025

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48391

Published May 20, 2025

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-47854

Published May 20, 2025

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 101-125 of 601 CVEsPage 5 of 25