Jenkins: known exploited vulnerabilities
Entries6No. 38
Ransomware-linked1
Products6
Latest2025-10-02
Added per year
By product
1
1
1
1
1
1
Entries
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2017-1000353 | Jenkins Jenkins | 2025-10-02 | 99.6% | Unknown |
| CVE-2024-23897 | Jenkins Jenkins Command Line Interface (CLI) | 2024-08-19 | 99.9% | Known |
| CVE-2015-5317 | Jenkins Jenkins User Interface (UI) | 2023-05-12 | 23.0% | Unknown |
| CVE-2019-1003029 | Jenkins Script Security Plugin | 2022-04-25 | 74.4% | Unknown |
| CVE-2019-1003030 | Jenkins Matrix Project Plugin | 2022-03-25 | 97.0% | Unknown |
| CVE-2018-1000861 | Jenkins Jenkins Stapler Web Framework | 2022-02-10 | 98.3% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
CISA KEV lists 6 Jenkins vulnerabilities (No. 38 of 288 vendors).