Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Jenkins Project — Vulnerabilities & Security Advisories 1545

Browse all 1545 CVE security advisories affecting Jenkins Project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jenkins is an open-source automation server primarily used for continuous integration and continuous delivery (CI/CD) pipelines. As a widely adopted tool in software development, it facilitates the building, testing, and deployment of code. Historically, the platform has been susceptible to numerous security flaws, with over 1,400 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities frequently involve remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from insecure default configurations or improper input validation. A notable incident occurred in 2019 when a critical RCE flaw allowed attackers to execute arbitrary commands on build agents. The Jenkins project has since implemented stricter security defaults and improved access controls to mitigate these risks. Despite these efforts, the sheer volume of historical CVEs highlights the complexity of securing a long-standing, feature-rich automation ecosystem, requiring diligent maintenance and configuration management by administrators to ensure robust protection against potential exploits.

CVE IDTitleCVSSSeverityPublished
CVE-2026-70448 Jenkins Ivy Report 安全漏洞 — Jenkins Ivy Report Plugin--2026-08-05
CVE-2026-70447 Jenkins AWS CodeBuild 安全漏洞 — Jenkins AWS CodeBuild Plugin--2026-08-05
CVE-2026-70446 Jenkins CodeSonar 安全漏洞 — Jenkins CodeSonar Plugin--2026-08-05
CVE-2026-70445 Jenkins Sauce OnDemand 安全漏洞 — Jenkins Sauce OnDemand Plugin--2026-08-05
CVE-2026-70444 Jenkins Violation Comments to GitLab 安全漏洞 — Jenkins Violation Comments to GitLab Plugin--2026-08-05
CVE-2026-70443 Jenkins Horreum 安全漏洞 — Jenkins Horreum Plugin--2026-08-05
CVE-2026-70442 Jenkins Google Chat Notification 安全漏洞 — Jenkins Google Chat Notification Plugin--2026-08-05
CVE-2026-70441 Jenkins Summary Display 安全漏洞 — Jenkins Summary Display Plugin--2026-08-05
CVE-2026-70440 Jenkins Qualys Container Scanning Connector 安全漏洞 — Jenkins Qualys Container Scanning Connector Plugin--2026-08-05
CVE-2026-70439 Jenkins XML Job to Job DSL 安全漏洞 — Jenkins XML Job to Job DSL Plugin--2026-08-05
CVE-2026-70438 Jenkins Parameterized Remote Trigger 安全漏洞 — Jenkins Parameterized Remote Trigger Plugin--2026-08-05
CVE-2026-70437 Jenkins Webhook Secret Credentials Provider 安全漏洞 — Jenkins Webhook Secret Credentials Provider Plugin--2026-08-05
CVE-2026-70436 Jenkins External Workspace Manager 安全漏洞 — Jenkins External Workspace Manager Plugin--2026-08-05
CVE-2026-70435 Jenkins SCM-Manager Plugin 安全漏洞 — Jenkins SCM-Manager Plugin--2026-08-05
CVE-2026-70434 Jenkins SCM-Manager Plugin 安全漏洞 — Jenkins SCM-Manager Plugin--2026-08-05
CVE-2026-70433 Jenkins HCL AppScan 安全漏洞 — Jenkins HCL AppScan Plugin--2026-08-05
CVE-2026-70432 Jenkins Multijob 跨站请求伪造漏洞 — Jenkins Multijob Plugin--2026-08-05
CVE-2026-70430 Jenkins 安全漏洞 — Jenkins--2026-08-05
CVE-2026-70431 Jenkins Multijob 代码注入漏洞 — Jenkins Multijob Plugin--2026-08-05
CVE-2026-70429 Jenkins 安全漏洞 — Jenkins--2026-08-05
CVE-2026-70427 Jenkins 后置链接漏洞 — Jenkins--2026-08-05
CVE-2026-70428 Jenkins 路径遍历漏洞 — Jenkins--2026-08-05
CVE-2026-70426 Jenkins 反序列化注入漏洞 — Jenkins--2026-08-05
CVE-2026-57307 Jenkins Project Jenkins Zowe zDevOps Plugin 授权问题漏洞 — Jenkins Zowe zDevOps Plugin--2026-06-24
CVE-2026-57306 Jenkins Project Jenkins Zowe zDevOps Plugin 跨站请求伪造漏洞 — Jenkins Zowe zDevOps Plugin--2026-06-24
CVE-2026-57305 Jenkins Project Jenkins Assembla Plugin 跨站请求伪造漏洞 — Jenkins Assembla Plugin--2026-06-24
CVE-2026-57303 Jenkins Project Jenkins Assembla Plugin 服务端请求伪造漏洞 — Jenkins Assembla Plugin--2026-06-24
CVE-2026-57304 Jenkins Project Jenkins Assembla Plugin 授权问题漏洞 — Jenkins Assembla Plugin--2026-06-24
CVE-2026-57302 Jenkins Project Jenkins FitNesse Plugin 信任管理问题漏洞 — Jenkins FitNesse Plugin--2026-06-24
CVE-2026-57300 Jenkins Project Jenkins MCP Server Plugin 授权问题漏洞 — Jenkins MCP Server Plugin--2026-06-24

This page lists every published CVE security advisory associated with Jenkins Project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.