Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f8h4-46xv-h7jj | Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file |
Tue, 05 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins html Publisher |
|
| CPEs | cpe:2.3:a:jenkins:html_publisher:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins html Publisher |
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins Html Publisher Plugin |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins Html Publisher Plugin |
Wed, 29 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting in Jenkins HTML Publisher Plugin |
Wed, 29 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 29 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-04-29T14:29:40.872Z
Reserved: 2026-04-28T09:24:35.049Z
Link: CVE-2026-42524
Updated: 2026-04-29T14:27:46.212Z
Status : Analyzed
Published: 2026-04-29T14:16:19.457
Modified: 2026-05-05T18:06:33.650
Link: CVE-2026-42524
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:21:18Z
Github GHSA