← Vulnerability feed

Vulnerability record · CVE-2023-25763 · published 15 February 2023

CVE-2023-25763: Jenkins email extension cross-site scripting vulnerability

Jenkins · Email Extension

Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.

5.4 CVSS 3.1 Medium EPSS 0.60% · top 53.3% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25763 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2023-25765Jenkins email extension vulnerabilityIn Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attack…EPSS 1.1%9.9CVE-2019-1003032Jenkins email extension vulnerabilityA sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudson/plugins/emailext/ExtendedEm…EPSS 2.4%8.8CVE-2026-48920Jenkins email extension vulnerabilityJenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attrib…EPSS 0.51%7.5CVE-2020-2232Jenkins email extension cleartext transmission vulnerabilityJenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,…EPSS 0.76%6.5CVE-2018-1000176Jenkins email extension information exposure vulnerabilityAn exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/email…EPSS 0.99%5.4CVE-2023-25764Jenkins email extension cross-site scripting vulnerabilityJenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during t…EPSS 0.60%5.3CVE-2017-2654Jenkins email extension information exposure vulnerabilityjenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically…EPSS 1.1%4.8CVE-2020-2253Jenkins email extension improper certificate validation vulnerabilityJenkins Email Extension Plugin 2.75 and earlier does not perform hostname validation when connecting to the configured SMTP server.EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2023-25763), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.