jenkins
1,755 tracked vulnerabilities.
CVE-2026-42525
MEDIUM
Jenkins Microsoft Entra ID Plugin <=666.v6060de32f87d - Open Redirect
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-42524
HIGH
Jenkins HTML Publisher Plugin < 427 - Stored Cross-Site Scripting in Legacy Wrapper File
Apr 29, 2026
CVSS 8.0
EPSS 0.00
CVE-2026-42523
CRITICAL
Jenkins GitHub Plugin < 1.46.0 - Stored Cross-Site Scripting via GitHub Hook Trigger Validation
Apr 29, 2026
CVSS 9.0
EPSS 0.00
CVE-2026-42522
MEDIUM
Jenkins GitHub Branch Source Plugin <=1967.vdea_d580c1a_b_a_ - Auth Bypass
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-42521
MEDIUM
Jenkins Project Jenkins Matrix Authorization Strategy Plugin < 3.2.9 - Information Disclosure
Apr 29, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-42520
HIGH
Jenkins Project Jenkins Credentials Binding Plugin < 719.v80e905ef14eb_ - Remote Code Execution
Apr 29, 2026
CVSS 7.5
EPSS 0.02
CVE-2026-42519
MEDIUM
Jenkins Script Security Plugin <=1399.ve6a_66547f6e1 - Info Disclosure
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33004
MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
Mar 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33003
MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
Mar 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33002
HIGH
Jenkins 2.426.3-2.554 - DNS Rebinding
Mar 18, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-33001
HIGH
Jenkins < 2.555 and LTS < 2.541.3 - Arbitrary File Write via Symbolic Link Handling in Archive Extraction
Mar 18, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-27100
MEDIUM
Jenkins < 2.551 and LTS < 2.541.2 - Exposure of Sensitive Build Information via Run Parameter
Feb 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-27099
HIGH
Jenkins 2.483-2.550 and LTS 2.492.1-2.541.1 - Stored Cross-Site Scripting in Offline Cause Description
Feb 18, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-67643
MEDIUM
Jenkins Redpen - Pipeline Reporter for Jira Plugin < 1.054.v7b_9517b_6b_202 Path Traversal
Dec 10, 2025
CVSS 4.3
EPSS 0.03
CVE-2025-67642
MEDIUM
Jenkins HashiCorp Vault Plugin <371.v884a_4dd60fb_6 - Privilege Esc...
Dec 10, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-67641
MEDIUM
Jenkins Coverage Plugin < 2.3054.ve1ff7b_a_a_123b - Stored Cross-Site Scripting via REST API Configuration
Dec 10, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-67640
MEDIUM
Jenkins Git client Plugin < 6.4.1 - OS Command Injection via Workspace Directory Name
Dec 10, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-67639
LOW
Jenkins < 2.528.3, 2.529-2.540 - Cross-Site Request Forgery
Dec 10, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-67638
MEDIUM
Jenkins < 2.528.3 and 2.529-2.540 - Cleartext Storage of Sensitive Information in Job Configuration Form
Dec 10, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-67637
MEDIUM
Jenkins < 2.528.3, 2.529-2.540 - Cleartext Storage of Build Authorization Tokens in config.xml
Dec 10, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-67636
MEDIUM
Jenkins < 2.528.3, 2.529-2.540 - Missing Authorization for Encrypted Password Viewing
Dec 10, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-67635
HIGH
Jenkins < 2.528.3 and 2.529-2.540 - Unauthenticated Denial of Service via HTTP CLI Connection Handling
Dec 10, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64150
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential Capture via URL Connection
Oct 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-64149
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-64148
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential ID Enumeration
Oct 29, 2025
CVSS 4.3
EPSS 0.00
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters