Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins bitbucket server integration plugin vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2025-24398
Jenkins Bitbucket Server Integration Plugin 2.1.0 up to and including 4.1.3 (both inclusive) allows malicious users to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
Jenkins Project Jenkins Bitbucket Server Integration Plugin
5.4
CVSSv3
CVE-2022-28134
Jenkins Bitbucket Server Integration Plugin 3.1.0 and previous versions does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
Jenkins Bitbucket Server Integration
5.4
CVSSv3
CVE-2022-28133
Jenkins Bitbucket Server Integration Plugin 3.1.0 and previous versions does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.
Jenkins Bitbucket Server Integration
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
type confusion
unspecified
CVE-2025-24200
reflected XSS
panel
CVE-2024-12549
temporal technologies, inc.
CVE-2024-21971
CVE-2024-57777
CVE-2023-31122
CVE-2025-0909
winzip computing
unified secops platform
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started