No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins buildgraph-view |
|
| CPEs | cpe:2.3:a:jenkins:buildgraph-view:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins buildgraph-view |
Wed, 27 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS via Unescaped Build URL in Jenkins Buildgraph‑View Plugin |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-05-27T15:20:35.672Z
Reserved: 2026-05-26T14:50:46.813Z
Link: CVE-2026-48927
Updated: 2026-05-27T15:20:27.763Z
Status : Analyzed
Published: 2026-05-27T15:16:32.410
Modified: 2026-05-28T16:52:13.477
Link: CVE-2026-48927
No data.
OpenCVE Enrichment
Updated: 2026-05-27T20:00:05Z