Jenkins Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2025-27624
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g. Build Queue and Build Executor Status widgets).