Jenkins Project

    Dashboard / Vendors

    Products: 66
    Vulnerabilities: 128
    Known Exploited: 0
    2
    Critical Level Threats
    41
    High Level Threats
    81
    Medium Level Threats
    4
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Items Per Page

    Vulnerabilities

    CVE-2026-84677

    Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.

    Last Modified: Sep 03, 2026
    Published: Sep 02, 2026

    CVE-2026-84676

    Tokens Stored Unencrypted in Jenkins Parameterized Remote Trigger Plugin

    Last Modified: Sep 03, 2026
    Published: Sep 02, 2026

    CVE-2026-84675

    OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

    Last Modified: Sep 03, 2026
    Published: Sep 02, 2026

    CVE-2026-84674

    Missing Permission Checks Allow Credential ID Enumeration in Jenkins XebiaLabs XL Deploy Plugin

    Last Modified: Sep 03, 2026
    Published: Sep 02, 2026

    CVE-2026-84673

    Stored XSS via Plugin Configuration Injection in Jenkins Customizable Header Plugin

    Last Modified: Sep 03, 2026
    Published: Sep 02, 2026
    Items Per Page