com.xuxueli:xxl-job-core
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.xuxueli:xxl-job-corepage 1 of 1
- CVE-2020-29204MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.3.02020-12-27
vulnerable: 1.4.1 ... 2.2.0 (24 versions)
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
- CVE-2022-40929CRITICALCVSS 9.8EG 9.82022-09-28
vulnerable: 1.4.1 ... 2.2.0 (24 versions)
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
- CVE-2022-43183HIGHCVSS 8.8EG 8.8✓ Fixed in 2.4.02022-11-17
vulnerable: 1.4.1 ... 2.3.1 (26 versions)
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
- CVE-2024-3366LOWCVSS 3.5EG 3.52024-04-06
vulnerable: 1.4.1 ... 2.4.0 (27 versions)
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipula…
- CVE-2024-42681HIGHCVSS 8.8EG 8.8✓ Fixed in 2.4.22024-08-15
vulnerable: 1.4.1 ... 2.4.1 (28 versions)
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
- CVE-2025-7787MEDIUMCVSS 6.3EG 6.32025-07-18
vulnerable: 1.4.1 ... 3.1.1 (33 versions)
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation lead…
Check whether com.xuxueli:xxl-job-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.xuxueli:xxl-job-core CVEs against the assets you own.
Start Free Scan →