References https://www.wangan.com/p/7fygf367ba2f2acc https://cve.imfht.com/detail/CVE-2020-2290 https://www.modb.pro/db/171741 https://bbs.antiy.cn/thread-96195-1-1.html https://github.com/advisories/GHSA-rp4x-h577-chvq https://www.jenkins.io/security/advisory/2021-11-12/ https://nvd.nist.gov/vuln/detail/CVE-2021-21699 https://feedly.com/cve/CVE-2021-21699 https://scanrepeat.com/vulnerability-database/active-choices-cross-site-scripting https://advisories.gitlab.com/pkg/maven/org.biouno/uno-choice/ https://stack.watch/product/jenkins/active-choices/ https://www.openwall.com/lists/oss-security/2021/11/12/1 https://docs.devguard.org/vulnerability-database/CVE-2021-21699/ https://feedly.com/cve/vendors/jenkins?page=9 https://www.cve.org/CVERecord?id=CVE-2021-21699
Related VulnerabilitiesPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalJenkins 代码执行漏洞(CVE-2026-84645)JeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞PoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure DeserializationPoCmixed-active-content: Mixed Active ContentPoCCVE-2026-3001: Gutenverse Plugin <= 3.4.6 - Cross-Site ScriptingPoCCVE-2025-6389: Sneeit WP Social WordPress Plugin - Unauthenticated RCE via call_user_funcPoCCVE-2026-3296: Everest Forms WordPress Plugin <= 3.4.3 - PHP Object InjectionStripe Payment Plugin for WooCommerce /wc-api/WT_Stripe/ SQL 注入漏洞(CVE-2024-0705)Jenkins /view 文件读取漏洞(CVE-2026-53435)PoCunauth-mulesoft-dataweave: MuleSoft DataWeave Interactive Learning Environment - Unauthenticated Access