CVE-2026-48927 PUBLISHED

Assigner: jenkins
Reserved: 26.05.2026 Published: 27.05.2026 Updated: 27.05.2026

Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.

Product Status

Vendor Jenkins Project
Product Jenkins buildgraph-view Plugin
Versions Default: unknown
  • affected from 0 to 1.8 (incl.)

References