CVE-2018-1000113: Jenkins Testlink

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript

Affected products

  • Jenkins Testlink: up to and including 3.12

Published 2018-03-13. Last modified 2026-06-17.