Jenkins Security Vulnerabilities (CVEs)

Track 192 security vulnerabilities affecting Jenkins products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

24 Critical
108 High
59 Medium
1 Low
🔔 Get Alerts for Jenkins
CVE-2026-27099 8.0

This stored cross-site scripting (XSS) vulnerability in Jenkins allows attackers with Agent/Configure or Agent/Disconnect permissions to inject malici...

Feb 18, 2026
CVE-2025-67636 4.3

This vulnerability in Jenkins allows attackers with View/Read permission to view encrypted password values in views. It affects Jenkins 2.540 and earl...

Dec 10, 2025
CVE-2025-67637 4.3

Jenkins versions 2.540 and earlier (including LTS 2.528.2 and earlier) store build authorization tokens unencrypted in job configuration files. This a...

Dec 10, 2025
CVE-2025-67638 4.3

Jenkins versions 2.540 and earlier (including LTS 2.528.2 and earlier) expose build authorization tokens in plain text on job configuration forms. Thi...

Dec 10, 2025
CVE-2025-67639 3.5

A CSRF vulnerability in Jenkins allows attackers to trick authenticated users into logging into the attacker's Jenkins account. This affects Jenkins 2...

Dec 10, 2025
CVE-2025-67640 5.0

This vulnerability in Jenkins Git client Plugin allows attackers who can control workspace directory names to inject arbitrary operating system comman...

Dec 10, 2025
CVE-2025-67641 5.4

This stored XSS vulnerability in Jenkins Coverage Plugin allows attackers with Item/Configure permission to inject malicious JavaScript via the REST A...

Dec 10, 2025
CVE-2025-67642 4.3

The Jenkins HashiCorp Vault Plugin vulnerability allows attackers with Item/Configure permission to access Vault credentials they shouldn't have acces...

Dec 10, 2025
CVE-2025-67643 4.3

The Jenkins Redpen - Pipeline Reporter for Jira Plugin vulnerability allows attackers with Item/Configure permission to bypass path validation and ret...

Dec 10, 2025
CVE-2025-67635 7.5

Jenkins versions 2.540 and earlier (including LTS 2.528.2 and earlier) have a vulnerability where HTTP-based CLI connections aren't properly closed wh...

Dec 10, 2025
CVE-2025-64144 4.3

The Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens in plaintext within job configuration files, allowing users with Item/Extended Read p...

Oct 29, 2025
CVE-2025-64145 4.3

The Jenkins ByteGuard Build Actions Plugin 1.0 fails to mask API tokens in the job configuration form, potentially exposing sensitive credentials to u...

Oct 29, 2025
CVE-2025-64146 4.3

The Jenkins Curseforge Publisher Plugin 1.0 stores API keys in plaintext within job configuration files, allowing users with Item/Extended Read permis...

Oct 29, 2025
CVE-2025-64147 4.3

The Jenkins Curseforge Publisher Plugin 1.0 displays API keys in plain text on job configuration forms instead of masking them. This allows attackers ...

Oct 29, 2025
CVE-2025-64148 4.3

The Jenkins Publish to Bitbucket Plugin before version 0.5 has a missing permission check that allows authenticated attackers with only Overall/Read p...

Oct 29, 2025
CVE-2025-64149 5.4

A CSRF vulnerability in Jenkins Publish to Bitbucket Plugin allows attackers to trick authenticated users into connecting Jenkins to attacker-controll...

Oct 29, 2025
CVE-2025-64150 5.4

This vulnerability in Jenkins Publish to Bitbucket Plugin allows attackers with Overall/Read permission to connect to attacker-controlled URLs using s...

Oct 29, 2025
CVE-2025-64137 4.3

The Jenkins Themis Plugin 1.4.1 and earlier contains a missing permission check vulnerability that allows authenticated attackers with Overall/Read pe...

Oct 29, 2025
CVE-2025-64138 4.3

A CSRF vulnerability in Jenkins Start Windocks Containers Plugin allows attackers to trick authenticated users into connecting Jenkins to attacker-con...

Oct 29, 2025
CVE-2025-64139 4.3

This vulnerability in Jenkins Start Windocks Containers Plugin allows attackers with Overall/Read permission to connect to arbitrary URLs, potentially...

Oct 29, 2025
CVE-2025-64140 8.8

The Jenkins Azure CLI Plugin vulnerability allows attackers with Item/Configure permission to execute arbitrary shell commands on the Jenkins controll...

Oct 29, 2025
CVE-2025-64142 4.3

The Jenkins Nexus Task Runner Plugin before version 0.9.3 has a missing permission check vulnerability. Attackers with Overall/Read permission can for...

Oct 29, 2025
CVE-2025-64143 4.3

The Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job configuration files, allowing users with Item/...

Oct 29, 2025
CVE-2025-64132 5.4

The Jenkins MCP Server Plugin vulnerability allows attackers to bypass permission checks and trigger unauthorized builds or access sensitive job/cloud...

Oct 29, 2025
CVE-2025-64133 5.4

A CSRF vulnerability in Jenkins Extensible Choice Parameter Plugin allows attackers to trick authenticated users into executing sandboxed Groovy code....

Oct 29, 2025
CVE-2025-64134 7.1

Jenkins JDepend Plugin 1.3.1 and earlier contains an XML external entity (XXE) vulnerability due to an outdated JDepend Maven Plugin dependency. This ...

Oct 29, 2025
CVE-2025-64136 4.3

A CSRF vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to trick authenticated users into making unintended requests to attac...

Oct 29, 2025
CVE-2025-59474 5.3

This vulnerability allows attackers without Overall/Read permission in Jenkins to list agent names through the sidepanel executors widget. It affects ...

Sep 17, 2025
CVE-2025-59475 4.3

This vulnerability in Jenkins allows authenticated attackers without Overall/Read permission to obtain limited information about Jenkins configuration...

Sep 17, 2025
CVE-2025-59476 5.3

This vulnerability allows attackers who can control log message content in Jenkins to insert line break characters followed by forged log messages. Th...

Sep 17, 2025
CVE-2025-58458 4.3

This vulnerability in Jenkins Git client Plugin allows attackers with Overall/Read permission to determine whether specific file paths exist on the Je...

Sep 3, 2025
CVE-2025-58459 4.3

The Jenkins global-build-stats plugin has a missing authorization vulnerability in its REST API endpoints. Attackers with Overall/Read permission can ...

Sep 3, 2025
CVE-2025-58460 4.2

The Jenkins OpenTelemetry Plugin vulnerability allows attackers with Overall/Read permission to exfiltrate Jenkins credentials by connecting to attack...

Sep 3, 2025
CVE-2025-53676 6.5

The Jenkins Xooa Plugin 0.0.7 and earlier stores sensitive deployment tokens unencrypted in Jenkins configuration files. This allows attackers with fi...

Jul 9, 2025
CVE-2025-53678 6.5

The Jenkins User1st uTester Plugin 1.1 and earlier stores JWT tokens unencrypted in global configuration files on the Jenkins controller. This allows ...

Jul 9, 2025
CVE-2025-53743 5.3

Jenkins Applitools Eyes Plugin versions 1.16.5 and earlier expose Applitools API keys in plain text on job configuration forms. This allows attackers ...

Jul 9, 2025
CVE-2025-53666 6.5

The Jenkins Dead Man's Snitch Plugin 0.1 stores sensitive authentication tokens unencrypted in job configuration files. This allows users with Item/Ex...

Jul 9, 2025
CVE-2025-53668 6.5

The Jenkins VAddy Plugin 1.2.8 and earlier stores VAddy API authentication keys unencrypted in job configuration files. This allows users with Item/Ex...

Jul 9, 2025
CVE-2025-53670 6.5

The Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores sensitive API keys and encryption keys unencrypted in job configuration files. This allow...

Jul 9, 2025
CVE-2025-53672 6.5

The Jenkins Kryptowire Plugin stores API keys unencrypted in configuration files, allowing attackers with file system access to steal sensitive creden...

Jul 9, 2025
CVE-2025-53674 5.3

The Jenkins Sensedia Api Platform tools Plugin 1.0 fails to mask the Sensedia API Manager integration token on the global configuration form, exposing...

Jul 9, 2025
CVE-2025-53656 6.5

The Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores sensitive credentials unencrypted in job configuration files on the Jenkins con...

Jul 9, 2025
CVE-2025-53658 5.4

Jenkins Applitools Eyes Plugin 1.16.5 and earlier contains a stored cross-site scripting (XSS) vulnerability where the Applitools URL is not properly ...

Jul 9, 2025
CVE-2025-53660 4.3

The Jenkins QMetry Test Management Plugin 1.13 and earlier exposes API keys in plain text on job configuration forms instead of masking them. This all...

Jul 9, 2025
CVE-2025-53662 6.5

The Jenkins IFTTT Build Notifier Plugin stores sensitive IFTTT Maker Channel Keys unencrypted in configuration files, allowing users with Item/Extende...

Jul 9, 2025
CVE-2025-53664 6.5

The Jenkins Apica Loadtest Plugin stores authentication tokens in plaintext within job configuration files, allowing users with Item/Extended Read per...

Jul 9, 2025
CVE-2025-53650 7.3

The Jenkins Credentials Binding Plugin versions 687.v619cb_15e923f and earlier expose sensitive credentials in error messages written to build logs. T...

Jul 9, 2025
CVE-2025-53652 8.2

The Jenkins Git Parameter Plugin vulnerability allows attackers with Item/Build permission to inject arbitrary values into Git parameters by bypassing...

Jul 9, 2025
CVE-2025-53654 6.5

The Jenkins Statistics Gatherer Plugin stores AWS Secret Keys unencrypted in global configuration files, allowing attackers with file system access to...

Jul 9, 2025
CVE-2025-5806 8.0

The Jenkins Gatling Plugin 136.vb_9009b_3d33a_e has a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into ...

Jun 6, 2025

Why Monitor Jenkins Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 192+ known vulnerabilities affecting Jenkins products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Jenkins packages in under 60 seconds. No agents required - completely agentless scanning that works across Jenkins deployments.

Free vulnerability database: Access detailed information about every Jenkins CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Jenkins CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Jenkins CVEs Free