CVE Tools

Jenkins

1,621 CVEs tracked since 2011. Since Nov 2019, 2 of them reached CISA KEV.

Jenkins CVEs per month

Nov 2019 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Jenkins CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-11150
2019-12280
2020-01210
2020-02260
2020-03380
2020-04null or fewer
2020-05null or fewer
2020-06110
2020-07null or fewer
2020-0890
2020-09480
2020-10130
2020-11210
2020-1250
2021-01140
2021-0270
2021-03null or fewer
2021-04100
2021-05130
2021-06160
2021-07null or fewer
2021-0850
2021-09null or fewer
2021-1030
2021-11200
2021-12null or fewer
2022-01240
2022-02420
2022-03520
2022-04170
2022-05280
2022-06860
2022-07440
2022-0830
2022-09320
2022-10350
2022-11240
2022-1270
2023-01380
2023-02110
2023-03null or fewer
2023-04200
2023-05360
2023-06100
2023-07320
2023-08190
2023-09270
2023-10131
2023-1170
2023-12160
2024-0191
2024-02null or fewer
2024-03160
2024-04null or fewer
2024-0560
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-1050
2024-1180
2024-12null or fewer
2025-0170
2025-02null or fewer
2025-0360
2025-04110
2025-0560
2025-06null or fewer
2025-07320
2025-08null or fewer
2025-0960
2025-10200
2025-11null or fewer
2025-1290
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0470
2026-05130
2026-06360
2026-07null or fewer
2026-08230
2026-09530

Products

The products that kept showing up in Jenkins's monthly top three, with their CVEs summed over those months.

  1. Jenkins10219 months
  2. Pipeline\183 months
  3. Jenkins Script Security Plugin122 months
  4. Active Directory72 months
  5. Jenkins Active Directory Plugin72 months
  6. Jenkins Pipeline: Shared Groovy Libraries Plugin61 month
  7. Jenkins Saml Single Sign On(Sso) Plugin61 month
  8. Code Dx51 month
  9. Deployment Dashboard51 month
  10. Jenkins Deployment Dashboard Plugin51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Jenkins.

  1. CVE-2026-92129Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission t...7.5
  2. CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item...8.0
  3. CVE-2026-92128Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from th...7.5
  4. CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts...8.8
  5. CVE-2026-92126Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to de...8.5
  6. CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type...8.8
  7. CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allo...8.8
  8. CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inh...8.8
  9. CVE-2026-84658Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to subm...4.3
  10. CVE-2026-84659Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, all...4.3
  11. CVE-2026-84657In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, all...4.2
  12. CVE-2026-84656A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they...4.3
  13. CVE-2026-84655Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names t...4.3
  14. CVE-2026-84653Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with...3.5
  15. CVE-2026-84652In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the...7.3

The record

Peak rank
#5 in Jun 2022
Busiest month shown
Jun 2022, 86 CVEs
Months with a KEV entry
2 since Nov 2019
Monthly snapshots
89 since 2011
Jenkins's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store