Official owasp zap
This hub aggregates every CVE we track for Official owasp zap, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Security Productsother
2
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2024-082026-07
Latest CVEs
The 2 most recently published vulnerabilities affecting Official owasp zap.
- CVE-2026-57301Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary...8.8
- CVE-2019-1003060Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.8.8
Product normalization is registry-driven with AI assist and human review. How it works