Vendor
Jenkins Project vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 31 vulnerabilities in Jenkins Project: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 2 exploited in the wild. The most recent, CVE-2026-57307, was published on 24 June 2026. 3 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 2
- Exploited in the wild
- 2
About Jenkins Project
Open source automation server for building, testing, and deploying software.
Jenkins Project technologies
Latest Jenkins Project vulnerabilities
- CVE-2026-57307: Jenkins Zowe zDevOps Plugin missing permission check in connection endpointmediumCVSS 4.2EPSS 0.2%
- CVE-2026-57306: Jenkins Zowe zDevOps Plugin CSRF in credential connection endpointmediumCVSS 4.2EPSS 0.2%
- CVE-2026-57305: Jenkins Assembla Plugin CSRF in connection endpointmediumCVSS 5.4EPSS 0.2%
- CVE-2026-57304: Jenkins Assembla Plugin missing permission check in connection endpointmediumCVSS 5.4EPSS 0.3%
- CVE-2026-57303: Jenkins Assembla Plugin XXE in XML parserhighCVSS 7.1EPSS 0.4%
- CVE-2026-57302: Jenkins FitNesse Plugin cleartext storage of passwords in job configmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57301: Jenkins OWASP ZAP Plugin arbitrary code execution on controllerhighCVSS 8.8EPSS 0.6%
- CVE-2026-57300: Jenkins MCP Server Plugin missing permission check in Pipeline replay scriptsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57299: Jenkins Contrast Continuous Application Security Plugin missing permission checkmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57298: Jenkins Contrast Continuous Application Security Plugin CSRFmediumCVSS 5.4EPSS 0.1%
- CVE-2026-57297: Jenkins Contrast Continuous Application Security Plugin missing permission checkmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57296: Jenkins External Workspace Manager Plugin path traversal in exwsAllocatehighCVSS 8.8EPSS 0.8%
- CVE-2026-57295: Jenkins EC2 Fleet Plugin CSRF in AWS credential connectionmediumCVSS 5.4EPSS 0.2%
- CVE-2026-57294: Jenkins EC2 Fleet Plugin missing permission check in AWS credential handlingmediumCVSS 5.4EPSS 0.3%
- CVE-2026-57293: Jenkins Gitee Plugin incorrect permission check allows credential ID enumerationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57292: Jenkins Gitee Plugin CSRF in connection endpointmediumCVSS 5.4EPSS 0.1%
- CVE-2026-57291: Jenkins Gitee Plugin missing permission check in connection endpointmediumCVSS 5.4EPSS 0.2%
- CVE-2026-57290: Jenkins Priority Sorter Plugin CSRF in global job priority configurationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57289: Jenkins Bitbucket Push and Pull Request Plugin disabled SSL validationmediumCVSS 4.8EPSS 0.2%
- CVE-2026-57287: Jenkins Job Configuration History Plugin information disclosure in configuration historymediumCVSS 4.3EPSS 0.2%
- CVE-2026-57286: Jenkins Git Parameter Plugin missing permission check in SCM metadata endpointmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57285: Jenkins GitHub Branch Source Plugin missing permission check in API endpointmediumCVSS 4.3EPSS 0.3%
- CVE-2026-57284: Jenkins Pipeline Groovy Plugin unrestricted instantiation in Snippet GeneratormediumCVSS 4.3EPSS 0.3%
- CVE-2026-57283: Jenkins Pipeline Groovy Plugin CSRF in Snippet GeneratormediumCVSS 4.3EPSS 0.2%
- CVE-2026-57282: Jenkins Git client Plugin OS command injection in SSH wrapper scriptmediumCVSS 5EPSS 0.3%
Most severe Jenkins Project vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2019-1003029: Jenkins Script Security Plugin Sandbox Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.9
- CVE-2024-23897: Jenkins Command Line Interface (CLI) Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-57296: Jenkins External Workspace Manager Plugin path traversal in exwsAllocatehighCVSS 8.8EPSS 0.8%
- CVE-2026-57301: Jenkins OWASP ZAP Plugin arbitrary code execution on controllerhighCVSS 8.8EPSS 0.6%
- CVE-2026-48921: Jenkins Pipeline: Groovy Libraries Plugin arbitrary file read via symbolic linkshighCVSS 7.5EPSS 0.3%
- CVE-2026-57303: Jenkins Assembla Plugin XXE in XML parserhighCVSS 7.1EPSS 0.4%
- CVE-2026-48916: Jenkins LDAP Plugin Remote Code Execution via LDAP ReferralsmediumCVSS 6.6EPSS 0.3%
- CVE-2026-57304: Jenkins Assembla Plugin missing permission check in connection endpointmediumCVSS 5.4EPSS 0.3%
- CVE-2026-57294: Jenkins EC2 Fleet Plugin missing permission check in AWS credential handlingmediumCVSS 5.4EPSS 0.3%
- CVE-2026-57291: Jenkins Gitee Plugin missing permission check in connection endpointmediumCVSS 5.4EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/jenkins-project.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jenkins Project vulnerabilities", https://junglewise.ai/threats/vendors/jenkins-project, 26 September 2026.