Jenkins Project

First CVE: Jan 22, 2019Active for: 8 years
1,516
CVEs Published
More CVEs Published than 93% of tracked CNAs
189.5
Avg CVEs / Year
More Avg CVEs / Year than 94% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 19% of tracked CNAs
0.2%
In CISA KEV
Higher KEV Rate than 80% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Jenkins Project as a CNA, 98.3% affect products that Jenkins Project develops as a vendor.

98.3%
Self-reported: 1,490Third-party: 26

Of all the CVEs published that affect products developed by Jenkins Project, 82.9% are self-published by Jenkins Project as a CNA.

82.9%
17.1%
Self-published: 1,490Published by other CNAs: 308

Trends Over Time

The number and severity of CVEs published by Jenkins Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2019
7 years ago
Most Recent CVE
Jun 24, 2026
30 days ago

Top CVEs

All CVEs published by Jenkins Project as a CNA, regardless of affected vendor or product.

1,516 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with t
Jan 24, 20249.899YESYES
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo
Mar 8, 20199.996YESYES
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, sr
Mar 8, 20199.996YESYES
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows
Jan 22, 20198.893NOYES
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenk
Jan 22, 20198.887NOYES
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/
Jan 22, 20198.886NOYES
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.
Jan 15, 20206.181NOYES
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability
Mar 9, 20206.172NOYES
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
Oct 23, 20196.172NOYES
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitab
Aug 12, 20205.470NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,516 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local47 (3.1%)
Network1,467 (96.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.1%)
Attack Complexity
Low1,453 (95.8%)
High63 (4.2%)
Unknown0 (0.0%)
User Interaction
None986 (65.0%)
Unknown0 (0.0%)
Required530 (35.0%)
Privileges Required
Low1,023 (67.5%)
High18 (1.2%)
None475 (31.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1516 CVEs).

CISA KEV
3 CVEs
0.2% of CVEs· 80th percentile
Metasploit
6 CVEs
0.4% of CVEs· 81st percentile
Nuclei
9 CVEs
0.6% of CVEs· 77th percentile
ExploitDB
11 CVEs
0.7% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Jenkins Project as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Jenkins Project as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs