Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84665

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Sep 02, 2026
Vendor unknown

Description

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

References