xxl-job vulnerabilities
CVEs whose affected-version data names the xxl-job package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-94426Low· 3.5A vulnerability was determined in xuxueli xxl-job up to 3.5.0
A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remo…
CVE-2026-94145Low· 3.5PoCA vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0
A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…
CVE-2026-90489Low· 3.5PoCA vulnerability was identified in Xuxueli xxl-job up to 3.5.0
A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed r…
CVE-2026-90488Medium· 6.3PoCA vulnerability was determined in Xuxueli xxl-job up to 3.4.2
A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…
CVE-2026-90487Medium· 4.3A vulnerability was found in Xuxueli xxl-job up to 3.4.2
A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation result…