Official Owasp Zap
2 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Official Owasp Zap, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Official Owasp Zap CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 2 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High2
Latest CVEs
The 2 most recently published vulnerabilities affecting Official Owasp Zap.
- CVE-2026-57301Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary...8.8
- CVE-2019-1003060Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.8.8
Product grouping is registry-driven, with AI assist and human review. How it works