Skip to main content

Vendor/product archive

jenkins / html_publisher CVEs

Beta · best-effort

7 CVEs tagged to jenkins / html_publisher0 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-42524

Published Apr 29, 2026

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitab…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53651

Published Jul 9, 2025

Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing inf…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-28151

Published Mar 6, 2024

Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/C…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28150

Published Mar 6, 2024

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site s…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28149

Published Mar 6, 2024

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site script…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10432

Published Oct 1, 2019

Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability explo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000175

Published May 8, 2018

A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1