← Back

Mashup Portlets

mashup_portlets

Vendor: Jenkins • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Mashup Portlets
Jun 17, 2026
Apr 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custom JavaScript expression, resulting in a stored cross-site scripting (XSS) vulner...Show more
Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custom JavaScript expression, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission.Show less
1Jenkins
1Mashup Portlets
Jun 17, 2026
Jul 11, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.