cbcvebase.
CVE-2025-53658
published 2025-07-09

CVE-2025-53658: Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS)…

PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.24%
15.4th percentile
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected

21 ranges
VendorProductVersion rangeFixed in
jenkinsapica_loadtest_plugin
jenkinsapplitools_eyes< 1.16.61.16.6
jenkinsapplitools_eyes_plugin
jenkinsaqua_security_scanner_plugin
jenkinscredentials_binding_plugin
jenkinsgit_parameter_plugin
jenkinshtml_publisher_plugin
jenkinsibm_cloud_devops_plugin
jenkinsifttt_build_notifier_plugin
jenkinskryptowire_plugin
jenkinsnouvola_divecloud_plugin
jenkinsqmetry_test_management_plugin
jenkinsreadyapi_functional_testing_plugin
jenkinssnitch_plugin
jenkinsstatistics_gatherer_plugin
jenkinstestsigma_test_plan_run_plugin
jenkinsuser1st_utester_plugin
jenkinsvaddy_plugin
jenkinswarrior_framework_plugin
jenkinsxooa_plugin
jenkins_projectjenkins_applitools_eyes_plugin<= 1.16.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.