Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jenkins Project

First CVE: Dec 1, 2011Active for: 15 yearsTotal CVEs: 1,798
47.6
VTI Score
High

Jenkins is an open-source automation server whose vulnerability profile is shaped by its role as a widely deployed pipeline and CI/CD orchestration platform, with a large footprint spanning the core Jenkins server, plugin ecosystem (including Pipeline and Script Security), and integrations such as Active Directory authentication. The vendor's exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, missing authorization checks, and insufficiently protected credentials—flaws characteristic of web-facing automation systems that interact with sensitive build artifacts and infrastructure secrets. A meaningful share of the vendor's disclosures reach serious severity, reflecting the elevated privilege and access scope that Jenkins often holds within development and deployment environments. Defenders should treat Jenkins deployments as trust-critical infrastructure, prioritize network isolation and access controls, and maintain close tracking of plugin updates alongside core server patches, since the extensible architecture means that third-party plugins frequently introduce new exposure vectors. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,798
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Jenkins Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2011
14 years ago
Most Recent CVE
Jun 24, 2026
29 days ago

Self-Reporting Analysis

Of all the CVEs published by Jenkins Project as a CNA, 98.3% affect products that Jenkins Project develops as a vendor.

98.3%
Self-reported: 1,490 (98.3%)
Third-party: 26 (1.7%)

Of all the CVEs published that affect products developed by Jenkins Project, 82.9% are self-published by Jenkins Project as a CNA.

82.9%
17.1%
Self-published: 1,490 (82.9%)
Other CNAs: 308 (17.1%)

Products(693 total)

Top CVEs

Signals from CVEs in this vendor scope (1798 CVEs).

1,798 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-23897CRITICAL
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with t
Jan 24, 20249.899YESYES
CVE-2017-1000353CRITICAL
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerabili
Jan 29, 20189.899YESYES
CVE-2018-1000861CRITICAL
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/Meta
Dec 10, 20189.898YESYES
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2019-1003030CRITICAL
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo
Mar 8, 20199.996YESYES
CVE-2019-1003029CRITICAL
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, sr
Mar 8, 20199.996YESYES
CVE-2019-1003000HIGH
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows
Jan 22, 20198.893NOYES
CVE-2016-9299CRITICAL
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP quer
Jan 12, 20179.893NOYES
CVE-2015-8103CRITICAL
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a proble
Nov 25, 20159.890NOYES
CVE-2016-0792HIGH
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, rel
Apr 7, 20168.888NOYES
View all 1,798 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,798 CVEs
67%
27%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local59 (3.3%)
Network1,686 (93.8%)
Unknown51 (2.8%)
Physical0 (0.0%)
Adjacent Network2 (0.1%)
Attack Complexity
Low1,660 (92.3%)
High87 (4.8%)
Unknown51 (2.8%)
User Interaction
None1,155 (64.2%)
Unknown51 (2.8%)
Required592 (32.9%)
Privileges Required
Low1,164 (64.7%)
High22 (1.2%)
None561 (31.2%)
Unknown51 (2.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (1798 CVEs).

CISA KEV
7 CVEs
0.4% of CVEs· 99th percentile
Metasploit
11 CVEs
0.6% of CVEs· 97th percentile
Nuclei
13 CVEs
0.7% of CVEs· 95th percentile
ExploitDB
19 CVEs
1.1% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jenkins Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jenkins Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jenkins Project's Products

View all 11 CNAs →

Top CWEs