org.jenkins-ci.plugins:htmlpublisher
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:htmlpublisherpage 1 of 1
- CVE-2018-1000175MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.162018-05-08
vulnerable: 0.7 ... 1.9 (18 versions)
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.
- CVE-2019-10432MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.212019-10-01
vulnerable: 0.7 ... 1.9 (24 versions)
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
- CVE-2024-28149MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.32.12024-03-06
vulnerable: 1.16 ... 1.32 (19 versions)
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jen…
- CVE-2024-28150MEDIUMCVSS 4.7EG 4.7✓ Fixed in 1.32.12024-03-06
vulnerable: 0.7 ... 1.9 (37 versions)
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with I…
- CVE-2024-28151MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.32.12024-03-06
vulnerable: 0.7 ... 1.9 (37 versions)
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenki…
- CVE-2026-42524HIGHCVSS 8.0EG 8.0✓ Fixed in 427.12026-04-29
vulnerable: 0.7 ... 427 (46 versions)
Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Check whether org.jenkins-ci.plugins:htmlpublisher is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:htmlpublisher CVEs against the assets you own.
Start Free Scan →