A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.
CVE ID: CVE-2025-47886
Vendor: Jenkins Project
Product: Jenkins Cadence vManager Plugin
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.24% (scored less or equal to compared to others)
EPSS Date: 2025-06-12 (when was this score calculated)