Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2023-28682
CVE-2023-28682
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Published Feb 11, 2026
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2928
CVSS Score
High
8.2
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
maven
org.jenkins-ci.plugins/perfpublisher
8.01
maven
org.jenkins-ci.plugins/perfpublisher
8.02
maven
org.jenkins-ci.plugins/perfpublisher
8.03
maven
org.jenkins-ci.plugins/perfpublisher
8.04
maven
org.jenkins-ci.plugins/perfpublisher
8.05
maven
org.jenkins-ci.plugins/perfpublisher
8.06
maven
org.jenkins-ci.plugins/perfpublisher
8.07
maven
org.jenkins-ci.plugins/perfpublisher
8.08
maven
org.jenkins-ci.plugins/perfpublisher
8.09
1-9 of 9
CVE-2023-28682 | Components Impacted | Sonatype Guide | Sonatype Guide