org.jenkins-ci.plugins

1,024 tracked vulnerabilities.

CVE-2026-42525 MEDIUM
Jenkins Microsoft Entra ID Plugin <=666.v6060de32f87d - Open Redirect
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-42524 HIGH
Jenkins HTML Publisher Plugin < 427 - Stored Cross-Site Scripting in Legacy Wrapper File
Apr 29, 2026
CVSS 8.0
EPSS 0.00
CVE-2026-42523 CRITICAL
Jenkins GitHub Plugin < 1.46.0 - Stored Cross-Site Scripting via GitHub Hook Trigger Validation
Apr 29, 2026
CVSS 9.0
EPSS 0.00
CVE-2026-42522 MEDIUM
Jenkins GitHub Branch Source Plugin <=1967.vdea_d580c1a_b_a_ - Auth Bypass
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-42521 MEDIUM
Jenkins Project Jenkins Matrix Authorization Strategy Plugin < 3.2.9 - Information Disclosure
Apr 29, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-42520 HIGH
Jenkins Project Jenkins Credentials Binding Plugin < 719.v80e905ef14eb_ - Remote Code Execution
Apr 29, 2026
CVSS 7.5
EPSS 0.02
CVE-2026-42519 MEDIUM
Jenkins Script Security Plugin <=1399.ve6a_66547f6e1 - Info Disclosure
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33004 MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
Mar 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33003 MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
Mar 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-67640 MEDIUM
Jenkins Git client Plugin < 6.4.1 - OS Command Injection via Workspace Directory Name
Dec 10, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-64150 MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential Capture via URL Connection
Oct 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-64149 MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-64148 MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential ID Enumeration
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64147 MEDIUM
Jenkins Curseforge Publisher Plugin 1.0 - Sensitive Data Exposure via Unmasked API Keys
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64146 MEDIUM
Jenkins Curseforge Publisher Plugin 1.0 - Unencrypted API Key Storage in config.xml
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64142 MEDIUM
Jenkins Nexus Task Runner Plugin <= 0.9.2 - Missing Authorization for URL Connection
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64141 MEDIUM
Jenkins Nexus Task Runner Plugin <= 0.9.2 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64140 HIGH
Jenkins Azure CLI Plugin < 0.9 - Authenticated OS Command Injection
Oct 29, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-64139 MEDIUM
Jenkins Start Windocks Containers Plugin < 1.4 - Missing Authorization
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64138 MEDIUM
Jenkins Start Windocks Containers Plugin < 1.4 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64137 MEDIUM
Jenkins Themis < 1.4.1 - Server-Side Request Forgery via Missing Permission Check
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64136 MEDIUM
Jenkins Themis Plugin < 1.4.1 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64134 HIGH
Jenkins JDepend Plugin < 1.3.1 - XML External Entity Injection
Oct 29, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-64131 HIGH
Jenkins SAML Plugin <4.583 - Auth Bypass
Oct 29, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-58459 MEDIUM
Jenkins global-build-stats Plugin < 322.v22f4db_18e2dd - Improper Access Control in REST API Endpoints
Sep 03, 2025
CVSS 4.3
EPSS 0.00