Xuxueli Xxl Job
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Xuxueli Xxl Job.
By the Year
In 2026 there have been 4 vulnerabilities in Xuxueli Xxl Job with an average score of 5.5 out of ten. Last year, in 2025 Xxl Job had 3 security vulnerabilities published. That is, 1 more vulnerability have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.04.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 5.48 |
| 2025 | 3 | 5.43 |
| 2024 | 3 | 9.13 |
| 2023 | 8 | 7.16 |
| 2022 | 5 | 8.32 |
It may take a day or so for new Xxl Job vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Xuxueli Xxl Job Security Vulnerabilities
XXL-Job 3.3.2 OpenAPI Endpoint Default_Token Hard-Coded Key Remote
CVE-2026-7306
5.6 - Medium
- April 28, 2026
A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token leads to use of hard-coded cryptographic key . It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed publicly and may be used.
Use of Hard-coded Cryptographic Key
XXL-JOB SSRF via triggerJob up to 3.3.2 - Xuxueli xxl-job
CVE-2026-7305
6.3 - Medium
- April 28, 2026
A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. There is ongoing doubt regarding the real existence of this vulnerability. The project maintainer explains (translated from Chinese): "Triggers are manually activated and involve login and access control, thus requiring management." The pull request by the researcher got rejected because of that.
SSRF
XXL-JOB logDetailCat logId identifier control vulnerability (<3.4.0, fixed 3.4.0)
CVE-2026-7303
3.7 - Low
- April 28, 2026
A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.4.0 is recommended to address this issue. The patch is identified as d24e4ccd6073cc75305e1d3b9c29bc8db7437e7a. It is suggested to upgrade the affected component.
Insecure Direct Object Reference
xxl-job 3.3.2 SSRF via JobInfoController - Xuxueli
CVE-2026-3733
6.3 - Medium
- March 08, 2026
A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit is now public and may be used. The project maintainer closed the issue report with the following statement: "Access token security verification is required." (translated from Chinese)
SSRF
XXL-Job 3.1.1 TokenGen Weak Hash Remotely
CVE-2025-7789
3.7 - Low
- July 18, 2025
A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational effort. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
Inadequate Encryption Strength
XXL-Job <3.1.1 SSRF via httpJobHandler (Critical)
CVE-2025-7787
6.3 - Medium
- July 18, 2025
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SSRF
Xuxueli Xxl-Job <=3.1.1 remote OS Command Injection
CVE-2025-7788
6.3 - Medium
- July 18, 2025
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Shell injection
Xxl-Job v2.4.1 Insecure Permissions in Sub-Task ID (RCE)
CVE-2024-42681
8.8 - High
- August 15, 2024
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
Incorrect Default Permissions
XXL-Job <2.4.1 Serialization Deserialization Injection (Template Handler)
CVE-2024-3366
9.8 - Critical
- April 06, 2024
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.
Marshaling, Unmarshaling
SSRF in xxl-job <= 2.4.1 enabling RCE via executor control
CVE-2024-24113
8.8 - High
- February 08, 2024
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
SSRF
XSS in xxl-job-admin 2.4.0 via /xxl-job-admin/joblog/logDetailPage
CVE-2023-48088
5.4 - Medium
- November 15, 2023
xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
XSS
XXL-Job-Admin 2.4.0 Insecure Permissions: /joblog/clearLog & logDetailCat
CVE-2023-48087
5.4 - Medium
- November 15, 2023
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.
Incorrect Permission Assignment for Critical Resource
xxl-job-admin 2.4.0 RCE via /xxl-job-admin/jobcode/save
CVE-2023-48089
8.8 - High
- November 15, 2023
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
CSRF in Xuxueli XXL-JOB v2.2.0 Admin Add Endpoint
CVE-2020-24922
8.8 - High
- August 11, 2023
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
Session Riding
XXL-Job 2.4.1 PrivEsc via /jobinfo POST to exec arbitrary cmds
CVE-2023-33779
8.8 - High
- May 26, 2023
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
XXL-Job RCE via HTML Upload in /xxl-job-admin/user/*
CVE-2023-26120
6.1 - Medium
- April 10, 2023
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
XSS
XXL-Job Permissions Bypass v2.2.0v2.3.1 via pageList
CVE-2023-27087
7.5 - High
- March 21, 2023
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.
XXL-JOB 2.3.1 CSRF in New Password Handler (/user/updatePwd)
CVE-2023-0674
6.5 - Medium
- February 04, 2023
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
Session Riding
XXL-Job SSRF via JobLogController (before 2.3.1)
CVE-2022-43183
8.8 - High
- November 17, 2022
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
SSRF
XXL-JOB 2.2.0 Cmd Exec in BaT (Background Tasks)
CVE-2022-40929
9.8 - Critical
- September 28, 2022
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Shell injection
XXL-JOB Insecure Permissions: Low-Privileged Execution of Admin Functions
CVE-2022-36157
8.8 - High
- August 19, 2022
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Improper Privilege Management
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability
CVE-2022-29770
5.4 - Medium
- June 03, 2022
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
XSS
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0
CVE-2022-29002
8.8 - High
- May 23, 2022
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
Session Riding
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Xuxueli Xxl Job or by Xuxueli? Click the Watch button to subscribe.