CVE-2026-42524

· NIST NVD ↗

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

HIGH
CVSS severity
8
CVSS base score
2026-04-29
Published

CWE codes

CWE-79

Affected products

jenkins:html_publisher

Sources