CVE-2026-100280
- EPSS 0.17%
- Veröffentlicht 30.09.2026 15:17:56
- Zuletzt bearbeitet 02.10.2026 15:47:12
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-100277
- EPSS 0.25%
- Veröffentlicht 30.09.2026 15:17:55
- Zuletzt bearbeitet 02.10.2026 16:01:53
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100278
- EPSS 0.24%
- Veröffentlicht 30.09.2026 15:17:55
- Zuletzt bearbeitet 02.10.2026 15:56:36
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100279
- EPSS 0.25%
- Veröffentlicht 30.09.2026 15:17:55
- Zuletzt bearbeitet 02.10.2026 15:49:59
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVE-2026-100275
- EPSS 0.22%
- Veröffentlicht 30.09.2026 15:17:54
- Zuletzt bearbeitet 02.10.2026 15:42:06
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-100276
- EPSS 0.22%
- Veröffentlicht 30.09.2026 15:17:54
- Zuletzt bearbeitet 02.10.2026 16:07:13
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100273
- EPSS 0.29%
- Veröffentlicht 30.09.2026 15:17:53
- Zuletzt bearbeitet 02.10.2026 16:30:38
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-100274
- EPSS 0.82%
- Veröffentlicht 30.09.2026 15:17:53
- Zuletzt bearbeitet 02.10.2026 16:18:48
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVE-2026-100270
- EPSS 0.17%
- Veröffentlicht 30.09.2026 15:17:52
- Zuletzt bearbeitet 02.10.2026 16:38:13
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100271
- EPSS 0.23%
- Veröffentlicht 30.09.2026 15:17:52
- Zuletzt bearbeitet 02.10.2026 16:33:51
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects