Cronicle is a job-scheduling and automation platform whose vulnerability exposure centers on its core product and reflects web-application attack surface risks, particularly cross-site scripting and missing authorization controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cronicle over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39401MEDIUM Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The | Apr 7, 2026 | 5.4 | 22 | NO | NO |
CVE-2026-39400MEDIUM Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges can inject arbi | Apr 7, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cronicle.
Media articles that mention a CVE ID that affects a product developed by Cronicle — matched by CVE ID, not by vendor name.