Stable in the CWE catalog · 24,491 CVEs mapped
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible