VYPR

Vendor CVEs

Xuxueli

All CVEs

34 total · sorted by risk
  • CVE-2022-40929CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

  • CVE-2024-24113HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

  • CVE-2023-48089HigNov 15, 2023
    risk 0.57cvss 8.8epss 0.01

    xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.

  • CVE-2020-24922HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

  • CVE-2023-33779HigMay 26, 2023
    risk 0.57cvss 8.8epss 0.01

    A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.

  • CVE-2022-29002HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.

  • CVE-2024-42681HigAug 15, 2024
    risk 0.50cvss 8.8epss 0.01

    Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

  • CVE-2022-43183HigNov 17, 2022
    risk 0.50cvss 8.8epss 0.02

    XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

  • CVE-2022-36157HigAug 19, 2022
    risk 0.50cvss 8.8epss 0.01

    XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.

  • CVE-2023-27087HigMar 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.

  • CVE-2020-23811HigSep 3, 2020
    risk 0.49cvss 7.5epss 0.01

    xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.

  • CVE-2018-20094HigDec 12, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.

  • CVE-2025-60645MedNov 12, 2025
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

  • CVE-2026-3733MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery. It is possible to launch the attack…

  • CVE-2025-7788MedJul 18, 2025
    risk 0.41cvss 6.3epss 0.05

    A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to os command…

  • CVE-2025-7787MedJul 18, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is…

  • CVE-2025-60646MedNov 12, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

  • CVE-2026-7306MedApr 28, 2026
    risk 0.36cvss 5.6epss 0.00

    A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the…

  • CVE-2025-9264MedAug 21, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper…

  • CVE-2023-48088MedNov 15, 2023
    risk 0.35cvss 5.4epss 0.00

    xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.

  • CVE-2023-48087MedNov 15, 2023
    risk 0.35cvss 5.4epss 0.00

    xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.

  • CVE-2023-26120MedApr 10, 2023
    risk 0.35cvss 5.4epss 0.00

    This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.

  • CVE-2022-29770MedJun 3, 2022
    risk 0.35cvss 5.4epss 0.01

    XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.

  • CVE-2026-7305MedApr 28, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument…

  • CVE-2020-29204MedDec 27, 2020
    risk 0.33cvss 6.1epss 0.01

    XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.

  • CVE-2020-23814MedSep 3, 2020
    risk 0.33cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.

  • CVE-2025-9263MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of…

  • CVE-2025-6700MedJun 26, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. The manipulation of the argument errorMsg leads to cross site scripting. The attack can be initiated remotely. The exploit has…

  • CVE-2023-0674MedFeb 4, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be…

  • CVE-2025-6701LowJun 26, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file /xxl-sso-server/doLogin. The manipulation of the argument redirect_url leads to open redirect. The attack may be initiated…

  • CVE-2026-7303LowApr 28, 2026
    risk 0.17cvss 3.7epss 0.00

    A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId…

  • CVE-2025-7789LowJul 18, 2025
    risk 0.17cvss 3.7epss 0.00

    A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to…

  • CVE-2024-3366LowApr 6, 2024
    risk 0.16cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has…

  • CVE-2026-65316MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can…