VulnSea

Jenkins Project has 16 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 6.7 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (4). Most affected products: Jenkins (4), Jenkins Bitbucket Push and Pull Request Plugin (1), Jenkins Bitbucket Server Integration Plugin (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.7
Publish → KEV
Last 90 days
14 prev 2

Products

  • Jenkins 4
  • Jenkins Bitbucket Push and Pull Request Plugin 1
  • Jenkins Bitbucket Server Integration Plugin 1
  • Jenkins Coverage Plugin 1
  • Jenkins GitLab Plugin 1
  • Jenkins Gitee Plugin 1
16
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Jenkins Project vulnerabilities

CVEs affecting Jenkins Project, newest first. Open any entry for full detail, references, and exploit status.

16 CVEsRSS

CVE-2026-92141Medium· 4.3
6d ago

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

SunlitJenkins Project · Jenkins Keycloak Authentication PluginEPSS 0.32%via NVD
CVE-2026-92140Medium· 6.8
6d ago

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger…

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger…

SunlitJenkins Project · Jenkins Gitee PluginEPSS 0.40%via NVD
CVE-2026-92139Medium· 6.5
6d ago

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bit…

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bit…

SunlitJenkins Project · Jenkins Bitbucket Push and Pull Request PluginEPSS 0.29%via NVD
CVE-2026-92138Medium· 4.2
6d ago

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack …

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack …

SunlitJenkins Project · Jenkins Bitbucket Server Integration PluginEPSS 0.10%via NVD
CVE-2026-92137High· 8.8
6d ago

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Config…

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Config…

TwilightJenkins Project · Jenkins Robot Framework PluginEPSS 0.78%via NVD
CVE-2026-92136High· 8.0
6d ago

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configu…

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configu…

TwilightJenkins Project · Jenkins OWASP Dependency-Check PluginEPSS 0.38%via NVD
CVE-2026-92135High· 8.0
6d ago

Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme …

Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme …

TwilightJenkins Project · Jenkins Coverage PluginEPSS 0.38%via NVD
CVE-2026-92134High· 8.0
6d ago

Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: sc…

Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: sc…

TwilightJenkins Project · Jenkins Warnings PluginEPSS 0.38%via NVD
CVE-2026-92133Medium· 5.4
6d ago

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials…

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials…

SunlitJenkins Project · Jenkins GitLab PluginEPSS 0.22%via NVD
CVE-2026-92132Medium· 5.4
6d ago

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able…

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able…

SunlitJenkins Project · Jenkins Gradle PluginEPSS 0.24%via NVD
CVE-2026-92131Medium· 4.2
6d ago

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside…

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside…

SunlitJenkins Project · Jenkins Pipeline: Groovy Libraries PluginEPSS 0.22%via NVD
CVE-2026-92130Low· 3.1
6d ago

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture cred…

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture cred…

SunlitJenkins Project · Jenkins Pipeline: Multibranch PluginEPSS 0.21%via NVD
CVE-2026-84649High· 8.8
2w ago

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serv…

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serv…

TwilightJenkins Project · JenkinsEPSS 0.17%via CVEORG
CVE-2026-84647High· 8.8
2w ago

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to…

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to…

TwilightJenkins Project · JenkinsEPSS 0.43%via CVEORG
CVE-2026-53437Medium· 4.3
3mo ago

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing …

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing …

SunlitJenkins Project · JenkinsEPSS 0.47%via CVEORG
CVE-2026-53435High· 8.8PoC
3mo ago

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows t…

MidnightJenkins Project · JenkinsEPSS 53%via CVEORG
Jenkins Project vulnerabilities (CVEs) · VulnSea