← Back

Vncrecorder

vncrecorder

Vendor: Jenkins • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Vncrecorder
Jun 17, 2026
Jul 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
1Jenkins
1Vncrecorder
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators...Show more
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.Show less