High
CVSS: 8.8
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
Medium
CVSS: 6.5
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Low
CVSS: 2.7
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
High
CVSS: 8.1
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
Medium
CVSS: 4.3
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
High
CVSS: 8.7
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
Medium
CVSS: 6.1
In JetBrains YouTrack before 2025.2.86935,
2025.2.87167,
2025.3.87341,
2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
High
CVSS: 7.6
In JetBrains YouTrack before 2025.2.86069,
2024.3.85077,
2025.1.86199 email spoofing via an administrative API was possible
High
CVSS: 7.7
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
Medium
CVSS: 4.3
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
High
CVSS: 7.1
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
Medium
CVSS: 5.5
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs