Jetbrains Teamcity vulnerabilities
276 known vulnerabilities affecting jetbrains/teamcity.
Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9
Vulnerabilities
Page 9 of 14
CVE-2022-48427P4MEDIUMCVSS 5.4fixed in 2022.10.32023-03-27
CVE-2022-48427 [MEDIUM] CWE-79 CVE-2022-48427: In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possib
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
nvd
CVE-2025-52875P4MEDIUMCVSS 5.4fixed in 2025.03.32025-06-23
CVE-2025-52875 [MEDIUM] CWE-79 CVE-2025-52875: In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
nvd
CVE-2024-56352P4MEDIUMCVSS 5.4fixed in 2024.122024-12-20
CVE-2024-56352 [MEDIUM] CWE-79 CVE-2024-56352: In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details pag
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
nvd
CVE-2024-56355P4MEDIUMCVSS 5.4fixed in 2024.122024-12-20
CVE-2024-56355 [MEDIUM] CWE-79 CVE-2024-56355: In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController respons
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
nvd
CVE-2021-25772P4MEDIUMCVSS 5.3fixed in 2020.2.22021-02-03
CVE-2021-25772 [MEDIUM] CVE-2021-25772: In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
nvd
CVE-2025-54537P4MEDIUMCVSS 5.5fixed in 2025.072025-07-28
CVE-2025-54537 [MEDIUM] CWE-312 CVE-2025-54537: In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
nvd
CVE-2021-3315P4MEDIUMCVSS 5.4fixed in 2020.2.22021-05-11
CVE-2021-3315 [MEDIUM] CWE-79 CVE-2021-3315: In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
nvd
CVE-2021-31908P4MEDIUMCVSS 5.4fixed in 2020.2.32021-05-11
CVE-2021-31908 [MEDIUM] CWE-79 CVE-2021-31908: In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
nvd
CVE-2023-41248P4MEDIUMCVSS 5.4fixed in 2023.05.32023-08-25
CVE-2023-41248 [MEDIUM] CWE-79 CVE-2023-41248: In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
nvd
CVE-2024-36363P4MEDIUMCVSS 5.4fixed in 2022.04.7≥ 2022.10, < 2022.10.6+3 more2024-05-29
CVE-2024-36363 [MEDIUM] CWE-79 CVE-2024-36363: In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code i
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
nvd
CVE-2024-36373P4MEDIUMCVSS 5.4fixed in 2024.03.22024-05-29
CVE-2024-36373 [MEDIUM] CWE-79 CVE-2024-36373: In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
nvd
CVE-2024-36369P4MEDIUMCVSS 5.4fixed in 2022.04.7≥ 2022.10, < 2022.10.6+3 more2024-05-29
CVE-2024-36369 [MEDIUM] CWE-79 CVE-2024-36369: In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
nvd
CVE-2022-46830P4MEDIUMCVSS 5.3≥ 2022.10, ≤ 2022.10.1≥ 2022.10, < 2022.10.12022-12-08
CVE-2022-46830 [MEDIUM] CWE-918 CVE-2022-46830: In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scan
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
nvd
CVE-2024-36375P4MEDIUMCVSS 5.3fixed in 2024.03.22024-05-29
CVE-2024-36375 [MEDIUM] CWE-209 CVE-2024-36375: In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be expo
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
nvd
CVE-2024-39878P4MEDIUMCVSS 5.3fixed in 2024.03.32024-07-01
CVE-2024-39878 [MEDIUM] CWE-522 CVE-2024-39878: In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connectio
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
nvd
CVE-2019-12844P4MEDIUMCVSS 6.1fixed in 2018.2.32019-07-03
CVE-2019-12844 [MEDIUM] CWE-94 CVE-2019-12844: A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issu
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
nvd
CVE-2020-15830P4MEDIUMCVSS 6.1fixed in 2019.2.32020-08-08
CVE-2020-15830 [MEDIUM] CWE-79 CVE-2020-15830: JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
nvd
CVE-2024-36367P4MEDIUMCVSS 6.1fixed in 2022.04.7≥ 2022.10, < 2022.10.6+3 more2024-05-29
CVE-2024-36367 [MEDIUM] CWE-79 CVE-2024-36367: In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party r
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
nvd
CVE-2020-15829P4MEDIUMCVSS 5.3fixed in 2019.2.32020-08-08
CVE-2020-15829 [MEDIUM] CWE-532 CVE-2020-15829: In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
nvd
CVE-2021-43194P4MEDIUMCVSS 5.3fixed in 2021.1.22021-11-09
CVE-2021-43194 [MEDIUM] CVE-2021-43194: In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
nvd