Jetbrains Teamcity vulnerabilities
276 known vulnerabilities affecting jetbrains/teamcity.
Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9
Vulnerabilities
Page 8 of 14
CVE-2023-34223P4MEDIUMCVSS 5.3fixed in 2023.052023-05-31
CVE-2023-34223 [MEDIUM] CWE-532 CVE-2023-34223: In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
nvd
CVE-2023-43566P4MEDIUMCVSS 5.4fixed in 2023.05.42023-09-19
CVE-2023-43566 [MEDIUM] CWE-79 CVE-2023-43566: In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
nvd
CVE-2025-47853P4MEDIUMCVSS 5.4fixed in 2025.03.22025-05-20
CVE-2025-47853 [MEDIUM] CWE-79 CVE-2025-47853: In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
nvd
CVE-2025-47852P4MEDIUMCVSS 5.4fixed in 2025.03.22025-05-20
CVE-2025-47852 [MEDIUM] CWE-79 CVE-2025-47852: In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
nvd
CVE-2019-18363P4MEDIUMCVSS 5.3fixed in 2019.1.22019-10-31
CVE-2019-18363 [MEDIUM] CVE-2019-18363: In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
nvd
CVE-2024-43807P4MEDIUMCVSS 5.4fixed in 2024.07.12024-08-16
CVE-2024-43807 [MEDIUM] CWE-79 CVE-2024-43807: In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
nvd
CVE-2024-41825P4MEDIUMCVSS 5.4fixed in 2024.072024-07-22
CVE-2024-41825 [MEDIUM] CWE-79 CVE-2024-41825: In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
nvd
CVE-2024-56349P4MEDIUMCVSS 5.3fixed in 2024.122024-12-20
CVE-2024-56349 [MEDIUM] CWE-862 CVE-2024-56349: In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify bu
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
nvd
CVE-2023-34222P4MEDIUMCVSS 6.1fixed in 2023.052023-05-31
CVE-2023-34222 [MEDIUM] CWE-79 CVE-2023-34222: In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
nvd
CVE-2019-12843P4MEDIUMCVSS 6.1fixed in 2018.2.32019-07-03
CVE-2019-12843 [MEDIUM] CWE-94 CVE-2019-12843: A possible stored JavaScript injection requiring a deliberate server administrator action was detect
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
nvd
CVE-2024-35300P4MEDIUMCVSS 6.1v2024.03≥ 2024.03, < 2024.03.12024-05-16
CVE-2024-35300 [MEDIUM] CWE-79 CVE-2024-35300: In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
nvd
CVE-2024-35302P4MEDIUMCVSS 6.1fixed in 2023.112024-05-16
CVE-2024-35302 [MEDIUM] CWE-79 CVE-2024-35302: In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
nvd
CVE-2025-68268P4MEDIUMCVSS 6.1fixed in 2025.11.12025-12-16
CVE-2025-68268 [MEDIUM] CWE-79 CVE-2025-68268: In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
nvd
CVE-2026-28194P4MEDIUMCVSS 6.1fixed in 2025.11.32026-02-25
CVE-2026-28194 [MEDIUM] CWE-601 CVE-2026-28194: In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
nvd
CVE-2022-48426P4MEDIUMCVSS 5.4v2022.10.3fixed in 2022.10.32023-03-27
CVE-2022-48426 [MEDIUM] CWE-79 CVE-2022-48426: In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
nvd
CVE-2023-38065P4MEDIUMCVSS 5.4fixed in 2023.05.12023-07-12
CVE-2023-38065 [MEDIUM] CWE-79 CVE-2023-38065: In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
nvd
CVE-2023-38063P4MEDIUMCVSS 5.4fixed in 2023.05.12023-07-12
CVE-2023-38063 [MEDIUM] CWE-79 CVE-2023-38063: In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
nvd
CVE-2023-38061P4MEDIUMCVSS 5.4fixed in 2023.05.12023-07-12
CVE-2023-38061 [MEDIUM] CWE-79 CVE-2023-38061: In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
nvd
CVE-2023-34229P4MEDIUMCVSS 5.4fixed in 2023.052023-05-31
CVE-2023-34229 [MEDIUM] CWE-79 CVE-2023-34229: In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
nvd
CVE-2023-34221P4MEDIUMCVSS 5.4fixed in 2023.052023-05-31
CVE-2023-34221 [MEDIUM] CWE-79 CVE-2023-34221: In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
nvd