---
id: CVE-2026-94145
title: A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0
summary: >-
  A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This
  vulnerability affects unknown code of the file
  xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java
  of the component Task Manag…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: xuxueli
product: xxl-job
affected:
  - xxl-job 3.0
  - xxl-job 3.1
  - xxl-job 3.2
  - xxl-job 3.3
  - xxl-job 3.4
  - xxl-job 3.4.0
  - xxl-job 3.4.1
  - xxl-job 3.4.2
  - xxl-job 3.5.0
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:17:29.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94145'
references:
  - url: 'https://github.com/hhhh333/CVE/blob/main/xxl-job-xss%202.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94145'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/893853'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408060'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408060/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T15:38:21.593357Z'
epss: 0.00191
epssPercentile: 0.09011
ingestedAt: '2026-09-21T07:33:19.003Z'
---

## Overview

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
