Description
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.
Published: 2026-05-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 30 May 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Buildgraph-view Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Buildgraph-view Plugin

Thu, 28 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins buildgraph-view
CPEs cpe:2.3:a:jenkins:buildgraph-view:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins buildgraph-view

Wed, 27 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unescaped Build URL in Jenkins Buildgraph‑View Plugin

Wed, 27 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.
References

Subscriptions

Jenkins Buildgraph-view
Jenkins Project Jenkins Buildgraph-view Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-05-27T15:20:35.672Z

Reserved: 2026-05-26T14:50:46.813Z

Link: CVE-2026-48927

cve-icon Vulnrichment

Updated: 2026-05-27T15:20:27.763Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T15:16:32.410

Modified: 2026-06-17T10:55:24.960

Link: CVE-2026-48927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-30T21:21:49Z

Weaknesses