| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration CVE-2026-103497 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications CVE-2026-103496 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs CVE-2026-103495 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes CVE-2026-103494 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible CVE-2026-103493 | Severity high |
| In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments CVE-2026-103492 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues CVE-2026-103491 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links CVE-2026-103490 | Severity high |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible CVE-2026-103489 | Severity medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access… CVE-2026-103488 | Severity high |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible CVE-2026-100280 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials CVE-2026-100279 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments CVE-2026-100278 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature CVE-2026-100277 | Severity critical |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action CVE-2026-100276 | Severity high |
| In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible CVE-2026-100275 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template CVE-2026-100274 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution CVE-2026-100273 | Severity critical |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read… CVE-2026-100272 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from… CVE-2026-100271 | Severity low |
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import… CVE-2026-100270 | Severity low |
| In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed CVE-2026-100269 | Severity medium |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates CVE-2026-100268 | Severity high |
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters CVE-2026-100267 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host CVE-2026-100264 | Severity low |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible CVE-2026-100263 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project… CVE-2026-100262 | Severity high |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission CVE-2026-100261 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset CVE-2026-100260 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access CVE-2026-100259 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings CVE-2026-100258 | Severity medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export CVE-2026-100257 | Severity medium |
| In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible CVE-2026-75051 | Severity high |
| In JetBrains YouTrack before 2026.1.13901,
2026.2.17950 doS attack was possible via crafted type parameters CVE-2026-75050 | Severity medium |
| In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the… CVE-2026-75049 | Severity medium |
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible CVE-2026-75048 | Severity high |
| In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint CVE-2026-75047 | Severity medium |
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint CVE-2026-75046 | Severity medium |
| In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via… CVE-2026-75045 | Severity critical |
| In JetBrains YouTrack before 2025.3.156085,
2026.1.13914,
2026.2.18095 missing authorisation allowed an authenticated user to delete… CVE-2026-75044 | Severity high |