Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-57295

CVE-2026-57295_CVE-2026-57295

A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to a...

Jenkins Project Jenkins EC2 Fleet Plugin CVE
MEDIUM 5.4 CVE-2026-57294

CVE-2026-57294_CVE-2026-57294

A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connec...

Jenkins Project Jenkins EC2 Fleet Plugin CVE
MEDIUM 4.3 CVE-2026-57293

CVE-2026-57293_CVE-2026-57293

An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (whi...

Jenkins Project Jenkins Gitee Plugin CVE
MEDIUM 5.4 CVE-2026-57292

CVE-2026-57292_CVE-2026-57292

A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attac...

Jenkins Project Jenkins Gitee Plugin CVE
MEDIUM 5.4 CVE-2026-57291

CVE-2026-57291_CVE-2026-57291

Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an a...

Jenkins Project Jenkins Gitee Plugin CVE
MEDIUM 4.3 CVE-2026-57290

CVE-2026-57290_CVE-2026-57290

A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite th...

Jenkins Project Jenkins Priority Sorter Plugin CVE
MEDIUM 4.8 CVE-2026-57289

CVE-2026-57289_CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connectio...

Jenkins Project Jenkins Bitbucket Push and Pull Request Plugin CVE
LOW 3.7 CVE-2026-57288

CVE-2026-57288_CVE-2026-57288

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI...

Jenkins Project Jenkins Active Directory Plugin CVE
MEDIUM 4.3 CVE-2026-57287

CVE-2026-57287_CVE-2026-57287

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historica...

Jenkins Project Jenkins Job Configuration History Plugin CVE
MEDIUM 4.3 CVE-2026-57286

CVE-2026-57286_CVE-2026-57286

A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain info...

Jenkins Project Jenkins Git Parameter Plugin CVE