CVE-2025-53677: Jenkins Xooa

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.

Affected products

  • Jenkins Xooa: up to and including 0.0.7

Published 2025-07-09. Last modified 2026-06-17.