Description
A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-12
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch or Update
AI Analysis

Impact

Xux any release up to 3.5.0, includes a cross‑site scripting flaw in the /jobinfo/insert API. An attacker can supply malicious content in the name or author parameters, which can be reflected to users who view the inserted job record, leading to execution of arbitrary scripts in the browser. This flaw is related to CWE‑79 and CWE‑94. The flaw is triggered by normal HTTP requests and does not require elevated privileges on the target system.

Affected Systems

Any deployment of Xuxueli xxl‑job that includes the /jobinfo/insert endpoint and is running version 3.5.0 or earlier is potentially impacted, as referenced by the CNA product name Xuxueli:xxl‑job.

Risk and Exploitability

The CVSS base score of 5.1 places the vulnerability in the medium severity range. The EPSS score of <1% indicates a low probability of exploitation, but the publicly available exploit means attackers have ready‑made tools to target the flaw by sending crafted HTTP requests to the /jobinfo/insert endpoint. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied update that addresses this flaw once it becomes available.
  • Implement server‑side input sanitization by stripping or HTML‑encoding the name and author fields before storing or rendering them, thereby preventing executable code from being inserted.
  • Configure a robust Content‑Security‑Policy header that disallows inline scripts and restricts script sources to trusted origins to mitigate script execution.
  • Validate incoming data against a whitelist of allowed characters, rejecting unexpected payloads to address the underlying CWE‑79 and CWE‑94 weaknesses.

Generated by OpenCVE AI on September 15, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Xuxueli xxl-job insert cross site scripting
First Time appeared Xuxueli
Xuxueli xxl-job
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:xuxueli:xxl-job:*:*:*:*:*:*:*:*
Vendors & Products Xuxueli
Xuxueli xxl-job
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T17:23:06.730Z

Reserved: 2026-09-12T08:03:37.754Z

Link: CVE-2026-90489

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:12.598Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T00:17:06.853

Modified: 2026-09-18T18:17:59.443

Link: CVE-2026-90489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')