Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file
High severity
GitHub Reviewed
Published
Apr 29, 2026
to the GitHub Advisory Database
•
Updated May 6, 2026
Package
Affected versions
< 427.1
Patched versions
427.1
Description
Published by the National Vulnerability Database
Apr 29, 2026
Published to the GitHub Advisory Database
Apr 29, 2026
Last updated
May 6, 2026
Reviewed
May 6, 2026
Jenkins HTML Publisher Plugin versoins 427 and earlier do not escape the job name and URL in the legacy wrapper file.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
HTML Publisher Plugin 427.1 escapes job name and URL when generating the legacy wrapper file.
References