Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Publish To Bitbucket MEDIUM 5.4
CVE-2025-64149

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-s…

Fix: after 0.4
Fix from $1,600 2025-10-29
Publish To Bitbucket MEDIUM 5.4
CVE-2025-64150

A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an atta…

Fix: after 0.4
Fix from $1,600 2025-10-29
Azure Cli HIGH 8.8
CVE-2025-64140

Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configu…

Fix: after 0.9
Fix from $1,950 2025-10-29
Saml HIGH 7.5
CVE-2025-64131

Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML …

Fix: 4.583.585.v22ccc1139f55+
Fix from $1,950 2025-10-29
Jdepend HIGH 7.1
CVE-2025-64134

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML e…

Fix: after 1.3.1
Fix from $1,950 2025-10-29
Eggplant Runner MEDIUM 5.9
CVE-2025-64135

Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an emp…

Fix: after 0.0.1.301.v963cffe8ddb_8
Fix from $1,600 2025-10-29
Mcp Server MEDIUM 5.4
CVE-2025-64132

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger bui…

Fix: 0.86.v7d3355e6a_a_18+
Fix from $1,600 2025-10-29
Extensible Choice Parameter MEDIUM 5.4
CVE-2025-64133

A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to exe…

Fix: after 239.v5f5c278708cf
Fix from $1,600 2025-10-29
Jenkins MEDIUM 5.3
CVE-2025-59474

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users l…

Fix: 2.516.3 / 2.528+
Fix from $1,600 2025-09-17
Jenkins MEDIUM 5.3
CVE-2025-59476

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in …

Fix: 2.516.3 / 2.528+
Fix from $1,600 2025-09-17
Warrior Framework MEDIUM 6.5
CVE-2025-53675

Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be vi…

Fix: after 1.2
Fix from $1,600 2025-07-09
Xooa MEDIUM 6.5
CVE-2025-53676

Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where …

Fix: after 0.0.7
Fix from $1,600 2025-07-09
User1st Utester MEDIUM 6.5
CVE-2025-53678

Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, w…

Fix: after 1.1
Fix from $1,600 2025-07-09
Applitools Eyes MEDIUM 6.5
CVE-2025-53742

Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where the…

Fix: 1.16.6+
Fix from $1,600 2025-07-09
Xooa MEDIUM 5.3
CVE-2025-53677

Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attacker…

Fix: after 0.0.7
Fix from $1,600 2025-07-09
Applitools Eyes MEDIUM 5.3
CVE-2025-53743

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential…

Fix: 1.16.6+
Fix from $1,600 2025-07-09
Dead Man\'s Snitch MEDIUM 6.5
CVE-2025-53666

Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be…

Mitigation only
Fix from $1,600 2025-07-09
Vaddy MEDIUM 6.5
CVE-2025-53668

Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be vi…

Fix: after 1.2.8
Fix from $1,600 2025-07-09
Nouvola Divecloud MEDIUM 6.5
CVE-2025-53670

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on th…

Fix: after 1.08
Fix from $1,600 2025-07-09
Nouvola Divecloud MEDIUM 6.5
CVE-2025-53671

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration…

Fix: after 1.08
Fix from $1,600 2025-07-09
Kryptowire MEDIUM 6.5
CVE-2025-53672

Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where…

Fix: after 0.2
Fix from $1,600 2025-07-09
Sensedia Api Platform Tools MEDIUM 6.5
CVE-2025-53673

Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the …

Mitigation only
Fix from $1,600 2025-07-09
Dead Man\'s Snitch MEDIUM 5.3
CVE-2025-53667

Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att…

Mitigation only
Fix from $1,600 2025-07-09
Sensedia Api Platform Tools MEDIUM 5.3
CVE-2025-53674

Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing …

Mitigation only
Fix from $1,600 2025-07-09
Readyapi Functional Testing MEDIUM 6.5
CVE-2025-53656

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.x…

Fix: after 1.11
Fix from $1,600 2025-07-09
Qmetry Test Management MEDIUM 6.5
CVE-2025-53659

Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controlle…

Fix: after 1.13
Fix from $1,600 2025-07-09
Ifttt Build Notifier MEDIUM 6.5
CVE-2025-53662

Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, wh…

Fix: after 1.2
Fix from $1,600 2025-07-09
Ibm Cloud Devops MEDIUM 6.5
CVE-2025-53663

Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controll…

Fix: after 2.0.16
Fix from $1,600 2025-07-09
Apica Loadtest MEDIUM 6.5
CVE-2025-53664

Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins con…

Fix: after 1.10
Fix from $1,600 2025-07-09
Applitools Eyes MEDIUM 5.4
CVE-2025-53658

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (X…

Fix: 1.16.6+
Fix from $1,600 2025-07-09