📦 Xxl Job

by Xuxueli

🔍 What is Xxl Job?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42681

HIGH CVSS 8.8 Aug 15, 2024

CVE-2024-42681 is an insecure permissions vulnerability in xxl-job v2.4.1 that allows remote attackers to execute arbitrary code via the Sub-Task ID component. This affects all deployments running the...

CVE-2024-24113

HIGH CVSS 8.8 Feb 8, 2024

This SSRF vulnerability in xxl-job allows low-privileged users to make the server execute arbitrary requests to internal systems, potentially leading to remote code execution. It affects all deploymen...

CVE-2023-48089

HIGH CVSS 8.8 Nov 15, 2023

xxl-job-admin 2.4.0 contains a remote code execution vulnerability in the /xxl-job-admin/jobcode/save endpoint. Attackers can execute arbitrary code on affected systems, potentially compromising the e...

CVE-2020-24922

HIGH CVSS 8.8 Aug 11, 2023

This CSRF vulnerability in xxl-job-admin allows attackers to create admin users via crafted HTML files, leading to privilege escalation and potential arbitrary code execution. It affects xxl-job versi...

CVE-2023-33779

HIGH CVSS 8.8 May 26, 2023

A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows authenticated users to execute arbitrary commands on other users' accounts via a crafted POST request to /jobinfo/. This enables a...

CVE-2023-27087

HIGH CVSS 7.5 Mar 21, 2023

A permissions vulnerability in Xuxueli xxl-job versions 2.2.0, 2.3.0, and 2.3.1 allows attackers to obtain sensitive information via the pageList parameter. This affects organizations using these vuln...

CVE-2025-9264

MEDIUM CVSS 5.4 Aug 21, 2025

This vulnerability in Xuxueli xxl-job allows remote attackers to manipulate job ID parameters to improperly control resource identifiers, potentially enabling unauthorized job deletion or manipulation...

CVE-2025-9263

MEDIUM CVSS 4.3 Aug 20, 2025

This vulnerability in Xuxueli xxl-job allows attackers to manipulate jobGroup parameters to improperly access resources. It affects xxl-job versions up to 3.1.1 and can be exploited remotely without a...

CVE-2025-7787

MEDIUM CVSS 6.3 Jul 18, 2025

This critical Server-Side Request Forgery (SSRF) vulnerability in Xuxueli xxl-job allows attackers to make unauthorized requests from the vulnerable server to internal or external systems. Attackers c...