Stored Cross-Site Scripting Vulnerability in Jenkins HTML Publisher Plugin
CVE-2026-42524
8HIGH
What is CVE-2026-42524?
The Jenkins HTML Publisher Plugin prior to version 428 is susceptible to a stored cross-site scripting (XSS) vulnerability. This occurs due to inadequate escaping of job names and URLs in the legacy wrapper file, enabling attackers with Item/Configure permissions to inject malicious scripts. This vulnerability can compromise the integrity of Jenkins instances and expose sensitive information if exploited.
Affected Version(s)
Jenkins HTML Publisher Plugin 0 <= 427