Skip to main content

Vendor/product archive

jetbrains / intellij_idea CVEs

Beta · best-effort

69 CVEs tagged to jetbrains / intellij_idea10 Critical, 19 High, 28 Medium, 12 Low, 0 Unrated.

CVE-2026-64815

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64814

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64813

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-64812

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-64811

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64810

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59792

Published Jul 10, 2026

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49383

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49382

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49367

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49366

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41882

Published Apr 30, 2026

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68269

Published Dec 16, 2025

In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57730

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57729

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57728

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-57727

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-32054

Published Apr 3, 2025

In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-37051

Published Jun 10, 2024

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2024-24941

Published Feb 6, 2024

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51655

Published Dec 21, 2023

In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 69 CVEsPage 1 of 3