CVE-2026-65316
- EPSS 0.38%
- Veröffentlicht 21.07.2026 21:23:55
- Zuletzt bearbeitet 23.07.2026 19:17:04
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetai...
CVE-2026-7306
- EPSS 0.33%
- Veröffentlicht 28.04.2026 19:30:13
- Zuletzt bearbeitet 24.07.2026 08:10:00
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoin...
CVE-2026-7305
- EPSS 0.21%
- Veröffentlicht 28.04.2026 19:15:13
- Zuletzt bearbeitet 24.07.2026 08:10:00
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manip...
CVE-2026-7303
- EPSS 0.42%
- Veröffentlicht 28.04.2026 19:00:17
- Zuletzt bearbeitet 24.07.2026 08:10:00
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manip...
CVE-2026-3733
- EPSS 0.21%
- Veröffentlicht 08.03.2026 11:15:50
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery. It is po...
CVE-2025-9264
- EPSS 0.34%
- Veröffentlicht 20.08.2025 23:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argum...
CVE-2025-9263
- EPSS 0.31%
- Veröffentlicht 20.08.2025 23:02:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup lea...
CVE-2025-7789
- EPSS 0.28%
- Veröffentlicht 18.07.2025 15:14:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. Th...
CVE-2025-7788
- EPSS 5.42%
- Veröffentlicht 18.07.2025 15:02:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipu...
CVE-2025-7787
- EPSS 0.42%
- Veröffentlicht 18.07.2025 14:14:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server...