21 entries matching jenkins — updated 2026-09-19 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-92122 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy crea | HIGH | 8.8 | 48%ile | NVD | 2026-09-16 |
| CVE-2026-92123 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null recei | HIGH | 8.8 | 47%ile | NVD | 2026-09-16 |
| CVE-2026-92124 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elem | HIGH | 8.8 | 47%ile | NVD | 2026-09-16 |
| CVE-2026-92125 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annot | HIGH | 8.8 | 43%ile | NVD | 2026-09-16 |
| CVE-2026-92137 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framewor | HIGH | 8.8 | 54%ile | NVD | 2026-09-16 |
| CVE-2026-92127 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item | HIGH | 8.0 | 40%ile | NVD | 2026-09-16 |
| CVE-2026-92134 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confi | HIGH | 8.0 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92135 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configurat | HIGH | 8.0 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92136 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the | HIGH | 8.0 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92128 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming | HIGH | 7.5 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-92129 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods | HIGH | 7.5 | 38%ile | NVD | 2026-09-16 |
| CVE-2026-92140 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in | MEDIUM | 6.8 | 34%ile | NVD | 2026-09-16 |
| CVE-2026-92139 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includin | MEDIUM | 6.5 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-92132 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected i | MEDIUM | 5.4 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-92133 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API to | MEDIUM | 5.4 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-92141 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attack | MEDIUM | 4.3 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-92131 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to | MEDIUM | 4.2 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-92138 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callb | MEDIUM | 4.2 | 1%ile | NVD | 2026-09-16 |
| CVE-2026-92130 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials | LOW | 3.1 | 12%ile | NVD | 2026-09-16 |
| CVE-2026-92126 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrat | UNKNOWN | — | 10%ile | NVD | 2026-09-16 |
| OSS-20260916-5 | Multiple vulnerabilities in Jenkins plugins | UNKNOWN | — | — | OSS-Security | 2026-09-16 |