Technology · Maven
org.jenkins-ci.plugins:script-security (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 36 vulnerabilities in org.jenkins-ci.plugins:script-security (Maven): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-57281, was published on 24 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 1
About org.jenkins-ci.plugins:script-security (Maven)
Jenkins plugin for controlling script execution and sandboxing in Jenkins jobs.
Latest org.jenkins-ci.plugins:script-security (Maven) vulnerabilities
- CVE-2026-57281: Jenkins Script Security Plugin sandbox bypass via Groovy AST annotationshighCVSS 7.5EPSS 0.9%
- CVE-2026-57280: Jenkins Script Security Plugin sandbox bypass via Groovy implicit type castshighCVSS 8.8EPSS 0.5%
- CVE-2026-42519: Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpathslowCVSS 3.1EPSS 0.3%
- CVE-2024-52549: Missing permission check in Jenkins Script Security PluginlowCVSS 3.1EPSS 0.4%
- CVE-2024-34145: Jenkins Script Security Plugin sandbox bypass vulnerabilitylowCVSS 3.1EPSS 1.0%
- CVE-2024-34144: Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodieslowCVSS 3.1EPSS 48.1%
- CVE-2023-24422: Sandbox bypass in Jenkins Script Security PluginlowCVSS 3.1EPSS 0.6%
- CVE-2022-45379: Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisionslowCVSS 3.1EPSS 0.5%
- CVE-2022-43403: Jenkins Script Security Plugin sandbox bypass vulnerabilitylowCVSS 3.1EPSS 1.6%
- CVE-2022-43404: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy PluginlowCVSS 3.1EPSS 1.2%
- CVE-2022-43401: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin and in Pipeline: Groovy PluginlowCVSS 3.1EPSS 1.3%
- CVE-2020-2190: Improper Neutralization of Input During Web Page Generation in Jenkins Script Security PluginlowCVSS 3.1EPSS 0.8%
- CVE-2020-2134: Sandbox bypass vulnerability in Script Security PluginlowCVSS 3.1EPSS 1.0%
- CVE-2020-2135: Sandbox bypass vulnerability in Script Security PluginlowCVSS 3.1EPSS 1.0%
- CVE-2020-2110: Improper Input Validation in Jenkins Script Security PluginlowCVSS 3.1EPSS 1.3%
- CVE-2019-16538: Incorrect Authorization in Jenkins Script Security PluginlowCVSS 3.1EPSS 1.4%
- CVE-2019-10431: Improper Control of Generation of Code in Jenkins Script Security PluginlowCVSS 3.1EPSS 2.7%
- CVE-2019-10399: Sandbox bypass vulnerability in Jenkins Script Security PluginlowCVSS 3.1EPSS 1.1%
- CVE-2019-10394: Sandbox bypass vulnerability in Jenkins Script Security PluginlowCVSS 3.1EPSS 1.1%
- CVE-2019-10400: Sandbox bypass vulnerability in Jenkins Script Security PluginlowCVSS 3.1EPSS 1.1%
- CVE-2019-10393: Sandbox bypass vulnerability in Script Security PluginlowCVSS 3.1EPSS 1.1%
- CVE-2019-10356: Return of Pointer Value Outside of Expected Rang in Jenkins Script Security PluginlowCVSS 3.1EPSS 2.5%
- CVE-2019-10355: Incorrect Privilege Assignment in Jenkins Script Security PluginlowCVSS 3.1EPSS 2.5%
- CVE-2022-30946: CSRF vulnerability in Jenkins Script Security PluginlowCVSS 3.1EPSS 0.6%
- CVE-2016-3102: Jenkins Script Security Plugin allows for Bypass of Groovy Sandbox ProtectionlowCVSS 3EPSS 1.8%
Most severe org.jenkins-ci.plugins:script-security (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2019-1003029: Sandbox bypass in Script Security Plugincriticalexploited in the wildCVSS 3.1EPSS 73.9%
- CVE-2026-57280: Jenkins Script Security Plugin sandbox bypass via Groovy implicit type castshighCVSS 8.8EPSS 0.5%
- CVE-2026-57281: Jenkins Script Security Plugin sandbox bypass via Groovy AST annotationshighCVSS 7.5EPSS 0.9%
- CVE-2019-1003000: Protection Mechanism Failure in Jenkins Script Security PluginlowCVSS 3.1EPSS 98.4%
- CVE-2019-1003001: Jenkins Groovy Plugin sandbox bypass vulnerabilitylowCVSS 3.1EPSS 86.1%
- CVE-2024-34144: Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodieslowCVSS 3.1EPSS 48.1%
- CVE-2019-1003005: Sandbox Bypass in Script Security PluginlowCVSS 3.1EPSS 19.0%
- CVE-2019-1003040: Sandbox bypass vulnerability in Jenkins Script Security PluginlowCVSS 3.1EPSS 3.4%
- CVE-2019-10431: Improper Control of Generation of Code in Jenkins Script Security PluginlowCVSS 3.1EPSS 2.7%
- CVE-2019-10356: Return of Pointer Value Outside of Expected Rang in Jenkins Script Security PluginlowCVSS 3.1EPSS 2.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-script-security.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "org.jenkins-ci.plugins:script-security (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-script-security, 28 September 2026.