MEDIUM

CVE-2026-92140

2026-09-16 CVSS v3.1
CVSS
6.8

Description

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.4%
Probability of exploitation in next 30 days
33.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE