CVE-2024-28150: Jenkins Html Publisher

Medium severity, CVSS 4.7. EPSS: 0.7% chance of exploitation in the next 30 days.

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected products

  • Jenkins Html Publisher: before 1.32.1 (fixed in 1.32.1)

Published 2024-03-06. Last modified 2026-06-17.