CVE-2023-28678: Jenkins Cppcheck
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.
Affected products
- Jenkins Cppcheck: up to and including 1.26
Published 2023-04-02. Last modified 2026-06-17.