๐Ÿ” CVE Alert

CVE-2026-92136

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Vendor jenkins project
Product jenkins owasp dependency-check plugin
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for jenkins project jenkins owasp dependency-check plugin

Be the first to know when new unknown vulnerabilities affecting jenkins project jenkins owasp dependency-check plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Jenkins Project / Jenkins OWASP Dependency-Check Plugin
0 โ‰ค 5.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
jenkins.io: https://www.jenkins.io/security/advisory/2026-09-16/#SECURITY-3992