← Back

Xuxueli

xuxueli

29 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Xxl Job
xxl-job
Xxl Sso
xxl-sso
Xxl Api
xxl-api
Xxl Conf
xxl-conf

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xuxueli
1Xxl Job
Jun 17, 2026
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
1Xuxueli
1Xxl Job
Jun 17, 2026
Sep 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of user...Show more
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).Show less
1Xuxueli
1Xxl Job
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
1Xuxueli
1Xxl Job
Jun 17, 2026
Jun 3, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
1Xuxueli
1Xxl Job
Jun 17, 2026
May 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
1Xuxueli
1Xxl Job
Jun 17, 2026
Dec 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
1Xuxueli
1Xxl Job
Jun 17, 2026
Sep 3, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.
1Xuxueli
1Xxl Job
Jun 17, 2026
Sep 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
1Xuxueli
1Xxl Conf
Nov 21, 2024
Dec 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.