← Back

Dotci

dotci

Vendor: Jenkins • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Dotci
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerabili...Show more
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.Show less
1Jenkins
1Dotci
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
1Jenkins
1Dotci
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.