CVE-2026-103496
- EPSS 0.14%
- Veröffentlicht 01.10.2026 09:15:27
- Zuletzt bearbeitet 01.10.2026 14:25:52
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-103497
- EPSS 0.15%
- Veröffentlicht 01.10.2026 09:15:27
- Zuletzt bearbeitet 01.10.2026 14:25:56
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVE-2026-103493
- EPSS 0.22%
- Veröffentlicht 01.10.2026 09:15:26
- Zuletzt bearbeitet 01.10.2026 16:17:36
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2026-103494
- EPSS 0.21%
- Veröffentlicht 01.10.2026 09:15:26
- Zuletzt bearbeitet 02.10.2026 04:18:04
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103495
- EPSS 0.2%
- Veröffentlicht 01.10.2026 09:15:26
- Zuletzt bearbeitet 01.10.2026 14:25:47
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVE-2026-103492
- EPSS 0.68%
- Veröffentlicht 01.10.2026 09:15:25
- Zuletzt bearbeitet 01.10.2026 14:19:33
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVE-2026-103490
- EPSS 0.43%
- Veröffentlicht 01.10.2026 09:15:24
- Zuletzt bearbeitet 05.10.2026 12:40:32
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103491
- EPSS 0.2%
- Veröffentlicht 01.10.2026 09:15:24
- Zuletzt bearbeitet 01.10.2026 14:28:17
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVE-2026-103488
- EPSS 0.28%
- Veröffentlicht 01.10.2026 09:15:23
- Zuletzt bearbeitet 05.10.2026 12:44:33
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-103489
- EPSS 0.14%
- Veröffentlicht 01.10.2026 09:15:23
- Zuletzt bearbeitet 05.10.2026 12:43:59
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible