cbcvebase.

Jetbrains Teamcity vulnerabilities

276 known vulnerabilities affecting jetbrains/teamcity.

Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9

Vulnerabilities

Page 7 of 14
CVE-2025-52877P4MEDIUMCVSS 4.8fixed in 2025.03.32025-06-23
CVE-2025-52877 [MEDIUM] CWE-79 CVE-2025-52877: In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
nvd
CVE-2020-11689P4MEDIUMCVSS 6.5fixed in 2019.2.12020-04-22
CVE-2020-11689 [MEDIUM] CWE-276 CVE-2020-11689: In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import set In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
nvd
CVE-2026-59795P4MEDIUMCVSS 6.1fixed in 2026.1.22026-07-10
CVE-2026-59795 [MEDIUM] CWE-79 CVE-2026-59795: In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
nvd
CVE-2025-47851P4MEDIUMCVSS 5.4fixed in 2025.03.22025-05-20
CVE-2025-47851 [MEDIUM] CWE-79 CVE-2025-47851: In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
nvd
CVE-2025-54538P4MEDIUMCVSS 5.5fixed in 2025.072025-07-28
CVE-2025-54538 [MEDIUM] CWE-312 CVE-2025-54538: In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
nvd
CVE-2024-24938P4MEDIUMCVSS 5.3fixed in 2023.11.22024-02-06
CVE-2024-24938 [MEDIUM] CWE-23 CVE-2024-24938: In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL do In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
nvd
CVE-2026-59794P4MEDIUMCVSS 5.4fixed in 2026.1.22026-07-10
CVE-2026-59794 [MEDIUM] CWE-79 CVE-2026-59794: In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-re In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
nvd
CVE-2025-67740P4MEDIUMCVSS 5.3fixed in 2025.112025-12-11
CVE-2025-67740 [MEDIUM] CWE-863 CVE-2025-67740: In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadat In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
nvd
CVE-2024-31140P4MEDIUMCVSS 4.9fixed in 2024.032024-03-28
CVE-2024-31140 [MEDIUM] CWE-1288 CVE-2024-31140: In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the ser In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
nvd
CVE-2025-24459P4MEDIUMCVSS 6.1fixed in 2024.12.12025-01-21
CVE-2025-24459 [MEDIUM] CWE-79 CVE-2025-24459: In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
nvd
CVE-2019-15848P4MEDIUMCVSS 6.1v2019.1v2019.1.12019-09-05
CVE-2019-15848 [MEDIUM] CWE-79 CVE-2019-15848: JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it poss JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
nvd
CVE-2024-47951P4MEDIUMCVSS 5.4fixed in 2024.07.32024-10-08
CVE-2024-47951 [MEDIUM] CWE-79 CVE-2024-47951: In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
nvd
CVE-2024-47950P4MEDIUMCVSS 5.4fixed in 2024.07.03fixed in 2024.07.32024-10-08
CVE-2024-47950 [MEDIUM] CWE-79 CVE-2024-47950: In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
nvd
CVE-2025-67741P4MEDIUMCVSS 5.4fixed in 2025.112025-12-11
CVE-2025-67741 [MEDIUM] CWE-79 CVE-2025-67741: In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
nvd
CVE-2024-24936P4MEDIUMCVSS 5.3fixed in 2023.11.22024-02-06
CVE-2024-24936 [MEDIUM] CWE-285 CVE-2024-24936: In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
nvd
CVE-2020-27627P4MEDIUMCVSS 6.1fixed in 2020.1.22020-11-16
CVE-2020-27627 [MEDIUM] CWE-74 CVE-2020-27627: JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection. JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
nvd
CVE-2025-26493P4MEDIUMCVSS 6.1fixed in 2024.12.22025-02-11
CVE-2025-26493 [MEDIUM] CWE-79 CVE-2025-26493: In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Re In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
nvd
CVE-2026-49375P4MEDIUMCVSS 6.1fixed in 2025.11.5fixed in 2026.1, 2025.11.52026-05-29
CVE-2026-49375 [MEDIUM] CWE-79 CVE-2026-49375: In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository downloa In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
nvd
CVE-2025-68166P4MEDIUMCVSS 6.1fixed in 2025.112025-12-16
CVE-2025-68166 [MEDIUM] CWE-79 CVE-2025-68166: In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
nvd
CVE-2024-28174P4MEDIUMCVSS 5.8fixed in 2023.11.42024-03-06
CVE-2024-28174 [MEDIUM] CWE-863 CVE-2024-28174: In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plug In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
nvd
Jetbrains Teamcity vulnerabilities | cvebase