org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2026-42525
MEDIUM
Jenkins Microsoft Entra ID Plugin <=666.v6060de32f87d - Open Redirect
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-42524
HIGH
Jenkins HTML Publisher Plugin < 427 - Stored Cross-Site Scripting in Legacy Wrapper File
Apr 29, 2026
CVSS 8.0
EPSS 0.00
CVE-2026-42523
CRITICAL
Jenkins GitHub Plugin < 1.46.0 - Stored Cross-Site Scripting via GitHub Hook Trigger Validation
Apr 29, 2026
CVSS 9.0
EPSS 0.00
CVE-2026-42522
MEDIUM
Jenkins GitHub Branch Source Plugin <=1967.vdea_d580c1a_b_a_ - Auth Bypass
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-42521
MEDIUM
Jenkins Project Jenkins Matrix Authorization Strategy Plugin < 3.2.9 - Information Disclosure
Apr 29, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-42520
HIGH
Jenkins Project Jenkins Credentials Binding Plugin < 719.v80e905ef14eb_ - Remote Code Execution
Apr 29, 2026
CVSS 7.5
EPSS 0.02
CVE-2026-42519
MEDIUM
Jenkins Script Security Plugin <=1399.ve6a_66547f6e1 - Info Disclosure
Apr 29, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33004
MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
Mar 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-33003
MEDIUM
Jenkins LoadNinja Plugin <=2.1 - Info Disclosure
Mar 18, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-67640
MEDIUM
Jenkins Git client Plugin < 6.4.1 - OS Command Injection via Workspace Directory Name
Dec 10, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-64150
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential Capture via URL Connection
Oct 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-64149
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-64148
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential ID Enumeration
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64147
MEDIUM
Jenkins Curseforge Publisher Plugin 1.0 - Sensitive Data Exposure via Unmasked API Keys
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64146
MEDIUM
Jenkins Curseforge Publisher Plugin 1.0 - Unencrypted API Key Storage in config.xml
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64142
MEDIUM
Jenkins Nexus Task Runner Plugin <= 0.9.2 - Missing Authorization for URL Connection
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64141
MEDIUM
Jenkins Nexus Task Runner Plugin <= 0.9.2 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64140
HIGH
Jenkins Azure CLI Plugin < 0.9 - Authenticated OS Command Injection
Oct 29, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-64139
MEDIUM
Jenkins Start Windocks Containers Plugin < 1.4 - Missing Authorization
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64138
MEDIUM
Jenkins Start Windocks Containers Plugin < 1.4 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64137
MEDIUM
Jenkins Themis < 1.4.1 - Server-Side Request Forgery via Missing Permission Check
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64136
MEDIUM
Jenkins Themis Plugin < 1.4.1 - Cross-Site Request Forgery
Oct 29, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-64134
HIGH
Jenkins JDepend Plugin < 1.3.1 - XML External Entity Injection
Oct 29, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-64131
HIGH
Jenkins SAML Plugin <4.583 - Auth Bypass
Oct 29, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-58459
MEDIUM
Jenkins global-build-stats Plugin < 322.v22f4db_18e2dd - Improper Access Control in REST API Endpoints
Sep 03, 2025
CVSS 4.3
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters