MEDIUM
CVE-2026-92140
CVSS
6.8
Description
Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.4%
Probability of exploitation in next 30 days
33.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.