---
id: CVE-2026-94426
title: A vulnerability was determined in xuxueli xxl-job up to 3.5.0
summary: >-
  A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted
  element is an unknown function of the file /jobgroup/insert. This manipulation
  of the argument Name causes cross site scripting. The attack can be initiated
  remo…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: xuxueli
product: xxl-job
affected:
  - xxl-job 3.0
  - xxl-job 3.1
  - xxl-job 3.2
  - xxl-job 3.3
  - xxl-job 3.4
  - xxl-job 3.5.0
published: '2026-09-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T23:19:21.993'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94426'
references:
  - url: 'https://github.com/hhhh333/CVE/blob/main/xxl-job-xss%20%204.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94426'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895569'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408152'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408152/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T22:55:16.217525Z'
epss: 0.00331
epssPercentile: 0.23435
ingestedAt: '2026-09-21T22:54:37.977Z'
---

## Overview

A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
