📦

email_extension

Vendor: jenkins

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 11 Total Indexed
Avg. EPSS 3.89% Exploit Prob.
Latest CVE CVE-2026-48920 May 27

Security Vulnerability Index

Page 2 / 2
6.5 CVSS

An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and ExtendedEmailPublisherDescriptor.java that allows attackers with control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured SMTP password.

EPSS: 0.09%