Xuxueli develops a focused suite of open-source workflow and job-scheduling components, with exposure centered on XXL-Job and related products in its identity and API management line. The vulnerability profile skews toward moderate severity outcomes, clustering in web application and authentication layers around cross-site scripting, cross-site request forgery, server-side request forgery, and authorization-bypass weaknesses that reflect the integration and request-handling demands of orchestration and access-control middleware. These weakness classes recur persistently across the product portfolio and are characteristic of the attack surface presented by developer-facing orchestration and authentication tools that sit between clients, task workers, and upstream services. Defenders deploying XXL-Job and XXL-SSO should prioritize input validation, CSRF protection, and access-control reviews in configuration and administration interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xuxueli over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-65316MEDIUM XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authoriz | Jul 21, 2026 | 6.5 | 31 | NO | NO |
CVE-2024-3366CRITICAL A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSeriali | Apr 6, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-40929CRITICAL XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running | Sep 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-23814MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in | Sep 3, 2020 | 6.1 | 29 | NO | YES |
CVE-2023-33779HIGH A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /job | May 26, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-43183HIGH XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java. | Nov 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-36157HIGH XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account. | Aug 19, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-29002HIGH A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add. | May 23, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-7788HIGH A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java | Jul 18, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-42681HIGH Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component. | Aug 15, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xuxueli.
Media articles that mention a CVE ID that affects a product developed by Xuxueli — matched by CVE ID, not by vendor name.