CVE-2023-25764: Jenkins Email Extension
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.
Affected products
- Jenkins Email Extension: before 2.93.1 (fixed in 2.93.1)
Published 2023-02-15. Last modified 2026-06-17.