CVE security advisories and vulnerability history for jenkins by jenkinsci.
192
Total CVEs
Published
3
In CISA KEV
Exploited in the wild
10
Public exploits
With known exploit
5.9
Avg CVSS
2016–2026
Last updated
Overview
jenkinsci jenkins has 192 published CVE records since 2016, of which 3 are in CISA's Known Exploited Vulnerabilities catalog and 10 have a known public exploit. The average CVSS base score across scored CVEs is 5.9.
This page aggregates every publicly disclosed vulnerability (CVE) affecting jenkinsci jenkins, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of jenkinsci jenkins's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical4
High15
Medium33
Low3
137 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
3
3 of jenkinsci jenkins's CVEs are confirmed exploited in the wild.
Public exploits
10
10 of jenkinsci jenkins's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every jenkinsci jenkins version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about jenkinsci jenkins vulnerabilities.
How many CVEs does jenkinsci jenkins have?
jenkinsci jenkins has 192 published CVE records since 2016.
How many jenkinsci jenkins CVEs are in CISA KEV?
Yes — 3 of jenkinsci jenkins's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for jenkinsci jenkins vulnerabilities?
Yes — 10 of jenkinsci jenkins's CVEs have a known public exploit.
Which versions of jenkinsci jenkins are affected?
1,967 distinct jenkinsci jenkins versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in jenkinsci jenkins CVEs?
jenkinsci jenkins's CVEs most often map to these CWE weakness types: CWE-862 (Missing Authorization), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-312 (Cleartext Storage of Sensitive Information), CWE-502 (Deserialization of Untrusted Data).
How many critical jenkinsci jenkins vulnerabilities are there?
jenkinsci jenkins has 4 critical and 15 high-severity CVEs.
What is the average severity of jenkinsci jenkins CVEs?
The average CVSS base score across jenkinsci jenkins's scored CVEs is 5.9.