Exposure of TeamCity
CI55
exposure score
1
sites use
4
exploited
6
critical
CVEs
188 resultsCVE-2025-46432MEDIUMIn JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logsEPSS 1.0%CVE-2022-48427MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possibleEPSS 1.0%CVE-2022-48426MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possibleEPSS 1.0%CVE-2025-52875MEDIUMIn JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possibleEPSS 1.0%CVE-2026-49377MEDIUMIn JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parametersEPSS 0.9%CVE-2025-59457HIGHIn JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on WindowsEPSS 0.8%CVE-2025-57734MEDIUMIn JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script filesEPSS 0.8%CVE-2025-67742LOWIn JetBrains TeamCity before 2025.11 path traversal was possible via file uploadEPSS 0.8%CVE-2024-56352MEDIUMIn JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details pageEPSS 0.8%CVE-2024-56355MEDIUMIn JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSSEPSS 0.8%CVE-2025-54534MEDIUMIn JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset pageEPSS 0.8%CVE-2024-24938MEDIUMIn JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentationEPSS 0.7%CVE-2025-47853MEDIUMIn JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possibleEPSS 0.7%CVE-2025-47852MEDIUMIn JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possibleEPSS 0.7%CVE-2022-36322MEDIUMIn JetBrains TeamCity before 2022.04.2 build parameter injection was possibleEPSS 0.7%CVE-2026-65907CRITICALIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possibleEPSS 0.7%CVE-2026-65906HIGHIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.7%CVE-2026-106219MEDIUMIn JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the serverEPSS 0.6%CVE-2015-1313—JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request daEPSS 0.6%CVE-2026-49373HIGHIn JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settingsEPSS 0.6%