org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2023-28683
HIGH
Jenkins Phabricator Differential Plugin <2.1.5 - XXE
Apr 02, 2023
CVSS 8.2
EPSS 0.01
CVE-2023-28682
HIGH
Jenkins Performance Publisher Plugin <8.09 - XXE
Apr 02, 2023
CVSS 8.2
EPSS 0.01
CVE-2023-28681
HIGH
Jenkins Visual Studio Code Metrics Plugin <1.7 - XXE
Apr 02, 2023
CVSS 8.2
EPSS 0.00
CVE-2023-28680
HIGH
Jenkins Crap4J Plugin < 0.9 - XML External Entity Injection
Apr 02, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-28678
MEDIUM
Jenkins Cppcheck Plugin <1.26 - XSS
Apr 02, 2023
CVSS 5.4
EPSS 0.09
CVE-2023-28677
CRITICAL
Jenkins Convert To Pipeline Plugin <1.0 - RCE
Apr 02, 2023
CVSS 9.8
EPSS 0.02
CVE-2023-28676
HIGH
Jenkins Convert To Pipeline Plugin <1.0 - CSRF
Apr 02, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-28669
MEDIUM
Jenkins JaCoCo Plugin < 3.3.2 - Stored Cross-Site Scripting via Unescaped Class and Method Names
Apr 02, 2023
CVSS 5.4
EPSS 0.09
CVE-2023-28668
CRITICAL
Jenkins Role-based Authorization Strategy Plugin <587.v2872c41fa_e5...
Apr 02, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-28685
HIGH
Jenkins AbsInt a³ Plugin <1.1.0 - XXE
Mar 22, 2023
CVSS 7.1
EPSS 0.01
CVE-2023-23850
MEDIUM
Synopsys Jenkins Coverity Plugin <3.0.2 - Info Disclosure
Feb 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-23848
MEDIUM
Synopsys Jenkins Coverity Plugin <3.0.2 - Privilege Escalation
Feb 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-23847
LOW
Synopsys Jenkins Coverity Plugin <3.0.2 - CSRF
Feb 15, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-25768
MEDIUM
Jenkins Azure Credentials Plugin < 254.v64da_8176c83a - Missing Authorization
Feb 15, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25767
HIGH
Jenkins Azure Credentials Plugin < 254.v64da_8176c83a - Cross-Site Request Forgery
Feb 15, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-25766
MEDIUM
Jenkins Azure Credentials Plugin < 254.v64da_8176c83a - Missing Authorization for Credential ID Enumeration
Feb 15, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-25765
CRITICAL
Jenkins Email Extension Plugin <2.93 - Code Injection
Feb 15, 2023
CVSS 9.9
EPSS 0.01
CVE-2023-25764
MEDIUM
Jenkins Email Extension Plugin < 2.93.1 - Stored Cross-Site Scripting via Email Template Rendering
Feb 15, 2023
CVSS 5.4
EPSS 0.21
CVE-2023-25763
MEDIUM
Jenkins Email Extension Plugin < 2.93.1 - Stored Cross-Site Scripting in Email Template Fields
Feb 15, 2023
CVSS 5.4
EPSS 0.21
CVE-2023-25762
MEDIUM
Jenkins Pipeline: Build Step Plugin < 2.18 - Stored Cross-Site Scripting via Job Name in Pipeline Snippet Generator
Feb 15, 2023
CVSS 5.4
EPSS 0.65
CVE-2023-25761
MEDIUM
Jenkins JUnit Plugin < 1166.va_436e268e972 - Stored Cross-Site Scripting via Test Case Class Names
Feb 15, 2023
CVSS 5.4
EPSS 0.02
CVE-2023-24459
MEDIUM
Jenkins BearyChat Plugin <3.0.2 - CSRF
Jan 26, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-24458
HIGH
Jenkins BearyChat Plugin <3.0.2 - CSRF
Jan 26, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-24457
MEDIUM
Jenkins Keycloak Auth Plugin <2.3.0 - CSRF
Jan 26, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-24456
CRITICAL
Jenkins Keycloak Authentication Plugin <2.3.0 - Info Disclosure
Jan 26, 2023
CVSS 9.8
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters