Jenkins
Jenkins Email Extension: vulnerabilities and CVEs
Jenkins Email Extension has 11 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs11
Last 12 months1
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48920 | High (8.8) | 0.51% | — | May 27, 2026 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined,… |
| CVE-2023-32980 | Medium (4.3) | 0.37% | — | May 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job. |
| CVE-2023-32979 | Medium (4.3) | 0.50% | — | May 16, 2023 | Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/… |
| CVE-2023-25765 | Critical (9.9) | 1.1% | — | Feb 15, 2023 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox… |
| CVE-2023-25764 | Medium (5.4) | 0.60% | — | Feb 15, 2023 | Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS)… |
| CVE-2023-25763 | Medium (5.4) | 0.60% | — | Feb 15, 2023 | Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control… |
| CVE-2020-2253 | Medium (4.8) | 0.69% | — | Sep 16, 2020 | Jenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server. |
| CVE-2020-2232 | High (7.5) | 0.76% | — | Aug 12, 2020 | Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure. |
| CVE-2019-1003032 | Critical (9.9) | 2.4% | — | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudson/plugins/emailext/ExtendedEmailPublisher.java,… |
| CVE-2017-2654 | Medium (5.3) | 1.1% | — | Aug 6, 2018 | jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM… |
| CVE-2018-1000176 | Medium (6.5) | 0.99% | — | May 8, 2018 | An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.