CVE Tools

Org.jenkins-ci.main:jenkins-core

247 CVEs tracked. 4 of them are in CISA KEV.

This hub aggregates every CVE we track for Org.jenkins-ci.main:jenkins-core, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Org.jenkins-ci.main:jenkins-core CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Org.jenkins-ci.main:jenkins-core CVEs per month
MonthCVEs
2024-102
2024-110
2024-120
2025-010
2025-020
2025-034
2025-042
2025-050
2025-060
2025-070
2025-080
2025-093
2025-100
2025-110
2025-125
2026-010
2026-022
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 247 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical187%
  • High5623%
  • Medium16266%
  • Low114%

Latest CVEs

The 15 most recently published vulnerabilities affecting Org.jenkins-ci.main:jenkins-core.

  1. CVE-2026-27100Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and It...4.3
  2. CVE-2026-27099Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting i...8.0
  3. CVE-2025-67639A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.3.5
  4. CVE-2025-67638Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.4.3
  5. CVE-2025-67637Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extend...4.3
  6. CVE-2025-67636A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.4.3
  7. CVE-2025-67635Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a den...7.5
  8. CVE-2025-59476Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control...5.3
  9. CVE-2025-59475Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain...4.3
  10. CVE-2025-59474Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attacke...5.3
  11. CVE-2025-31721A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining...4.3
  12. CVE-2025-31720A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gai...4.3
  13. CVE-2025-27625In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a...4.3
  14. CVE-2025-27624A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e...5.4
  15. CVE-2025-27623Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission...4.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store