- EPSS 0.19%
- Veröffentlicht 21.09.2026 22:30:08
- Zuletzt bearbeitet 24.09.2026 23:19:21
A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exp...
- EPSS 0.19%
- Veröffentlicht 21.09.2026 06:45:09
- Zuletzt bearbeitet 21.09.2026 16:17:29
A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interfa...
- EPSS 0.19%
- Veröffentlicht 12.09.2026 23:45:11
- Zuletzt bearbeitet 18.09.2026 18:17:59
A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The ...
CVE-2026-90488
- EPSS 0.23%
- Veröffentlicht 12.09.2026 23:15:19
- Zuletzt bearbeitet 15.09.2026 15:17:27
A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote explo...
CVE-2026-90487
- EPSS 0.21%
- Veröffentlicht 12.09.2026 23:00:11
- Zuletzt bearbeitet 14.09.2026 20:56:48
A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper...
CVE-2026-65316
- EPSS 0.38%
- Veröffentlicht 21.07.2026 21:23:55
- Zuletzt bearbeitet 23.07.2026 19:17:04
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetai...
CVE-2026-7306
- EPSS 0.33%
- Veröffentlicht 28.04.2026 19:30:13
- Zuletzt bearbeitet 24.07.2026 08:10:00
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoin...
CVE-2026-7305
- EPSS 0.21%
- Veröffentlicht 28.04.2026 19:15:13
- Zuletzt bearbeitet 24.07.2026 08:10:00
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manip...
CVE-2026-7303
- EPSS 0.42%
- Veröffentlicht 28.04.2026 19:00:17
- Zuletzt bearbeitet 24.07.2026 08:10:00
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manip...
CVE-2026-3733
- EPSS 0.21%
- Veröffentlicht 08.03.2026 11:15:50
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery. It is po...