Jenkins Project
First CVE: Jan 22, 2019Active for: 8 years
1,516
CVEs Published
More CVEs Published than 93% of tracked CNAs
189.5
Avg CVEs / Year
More Avg CVEs / Year than 94% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 19% of tracked CNAs
0.2%
In CISA KEV
Higher KEV Rate than 80% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Jenkins Project as a CNA, 98.3% affect products that Jenkins Project develops as a vendor.
98.3%
Self-reported: 1,490Third-party: 26
Of all the CVEs published that affect products developed by Jenkins Project, 82.9% are self-published by Jenkins Project as a CNA.
82.9%
17.1%
Self-published: 1,490Published by other CNAs: 308
Trends Over Time
The number and severity of CVEs published by Jenkins Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2019
7 years ago
Most Recent CVE
Jun 24, 2026
30 days ago
Top CVEs
All CVEs published by Jenkins Project as a CNA, regardless of affected vendor or product.
1,516 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23897CRITICAL Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with t | Jan 24, 2024 | 9.8 | 99 | YES | YES |
CVE-2019-1003030CRITICAL A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2019-1003029CRITICAL A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, sr | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2019-1003000HIGH A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows | Jan 22, 2019 | 8.8 | 93 | NO | YES |
CVE-2019-1003001HIGH A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenk | Jan 22, 2019 | 8.8 | 87 | NO | YES |
CVE-2019-1003002HIGH A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/ | Jan 22, 2019 | 8.8 | 86 | NO | YES |
CVE-2020-2096MEDIUM Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability. | Jan 15, 2020 | 6.1 | 81 | NO | YES |
CVE-2020-2140MEDIUM Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability | Mar 9, 2020 | 6.1 | 72 | NO | YES |
CVE-2019-10475MEDIUM A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin. | Oct 23, 2019 | 6.1 | 72 | NO | YES |
CVE-2020-2230MEDIUM Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitab | Aug 12, 2020 | 5.4 | 70 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,516 CVEs
68%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local47 (3.1%)
Network1,467 (96.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.1%)
Attack Complexity
Low1,453 (95.8%)
High63 (4.2%)
Unknown0 (0.0%)
User Interaction
None986 (65.0%)
Unknown0 (0.0%)
Required530 (35.0%)
Privileges Required
Low1,023 (67.5%)
High18 (1.2%)
None475 (31.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1516 CVEs).
CISA KEV
3 CVEs
0.2% of CVEs· 80th percentile
Metasploit
6 CVEs
0.4% of CVEs· 81st percentile
Nuclei
9 CVEs
0.6% of CVEs· 77th percentile
ExploitDB
11 CVEs
0.7% of CVEs· 80th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Jenkins Project as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Jenkins Project as a CNA — matched by CVE ID, not by organization name.