VYPR

xxl-job-admin

by Xxl Job

CVEs (4)

  • CVE-2026-52371Jul 31, 2026
    risk 0.00cvss epss 0.00

    A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

  • CVE-2026-65316Jul 21, 2026
    risk 0.00cvss epss 0.00

    XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can…

  • CVE-2026-26718Jul 15, 2026
    risk 0.00cvss epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP…

  • CVE-2026-26719Jul 15, 2026
    risk 0.00cvss epss 0.00

    Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script