Jenkins Project Jenkins Html Publisher Plugin vulnerabilities
5 known vulnerabilities affecting jenkins_project/jenkins_html_publisher_plugin.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2025-53651MEDIUMCVSS 6.3≤ 4252025-07-09
CVE-2025-53651 [MEDIUM] CWE-36 CVE-2025-53651: Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths
Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the Jenkins controller file system in the build log.
cvelistv5nvd
CVE-2024-28149MEDIUMCVSS 6.5≥ 1.16, ≤ 1.322024-03-06
CVE-2024-28149 [MEDIUM] CWE-79 CVE-2024-28149: Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, a
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
cvelistv5nvd
CVE-2024-28151MEDIUMCVSS 4.3≤ 1.322024-03-06
CVE-2024-28151 [MEDIUM] CWE-22 CVE-2024-28151: Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it.
cvelistv5nvd
CVE-2024-28150MEDIUMCVSS 4.7≤ 1.322024-03-06
CVE-2024-28150 [MEDIUM] CWE-79 CVE-2024-28150: Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index pa
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
cvelistv5nvd
CVE-2019-10432MEDIUMCVSS 5.4v1.20 and earlier2019-10-01
CVE-2019-10432 [MEDIUM] CWE-79 CVE-2019-10432: Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
cvelistv5nvd