Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.4
CVE-2026-84677
- EPSS 0.14%
- Veröffentlicht 02.09.2026 15:40:59
- Zuletzt bearbeitet 03.09.2026 17:13:16
Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacker...
9.6
CVE-2023-27905
- EPSS 1.54%
- Veröffentlicht 10.03.2023 21:15:15
- Zuletzt bearbeitet 28.02.2025 19:15:36
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for h...
1