VYPR

SonarQube Scanner Plugin

by Jenkins Project

CVEs (1)

  • CVE-2026-84665HigSep 2, 2026
    risk 0.52cvss 8.0epss

    Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with…