Skip to main content

Vendor/product archive

jenkins / email_extension CVEs

Beta · best-effort

11 CVEs tagged to jenkins / email_extension2 Critical, 2 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2026-48920

Published May 27, 2026

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on t…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-32980

Published May 16, 2023

A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32979

Published May 16, 2023

Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the exist…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25765

Published Feb 15, 2023

In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templ…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25764

Published Feb 15, 2023

Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25763

Published Feb 15, 2023

Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2253

Published Sep 16, 2020

Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2232

Published Aug 12, 2020

Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1003032

Published Mar 8, 2019

A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudson/plugins/emailext/ExtendedEmailPublisher.java, src/main/ja…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-2654

Published Aug 6, 2018

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based o…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1000176

Published May 8, 2018

An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/glo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1