Technology · XXL-JOB
XXL-JOB vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in XXL-JOB: 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-90489, was published on 13 September 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 0
- Exploited in the wild
- 0
About XXL-JOB
XXL-JOB is a distributed task scheduling framework.
Latest XXL-JOB vulnerabilities
- CVE-2026-90489: Xuxueli xxl-job cross-site scripting in job info insertlowCVSS 3.5EPSS 0.3%
- CVE-2026-90488: Xuxueli xxl-job remote code execution in Groovy class loadermediumCVSS 6.3EPSS 0.4%
- CVE-2026-90487: Xuxueli xxl-job privilege escalation in JobGroupControllermediumCVSS 4.3EPSS 0.4%
- CVE-2026-52371: XXL-JOB SSRF in jobinfo trigger componentinfoCVSS 0
- CVE-2026-65316: xuxueli XXL-JOB IDOR in logDetailCat endpointmediumCVSS 6.5
- CVE-2026-26719: xxl-job xxl-job-admin stored XSS in JobInfoControllerinfoCVSS 0
- CVE-2026-7306: Xuxueli xxl-job hard-coded default token in OpenAPI endpointmediumCVSS 5.6EPSS 0.3%
- CVE-2026-7305: Xuxueli xxl-job SSRF in trigger EndpointmediumCVSS 6.3EPSS 0.2%
- CVE-2026-7303: Xuxueli xxl-job IDOR in Execution Log HandlerlowCVSS 3.7EPSS 0.7%
Most severe XXL-JOB vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-65316: xuxueli XXL-JOB IDOR in logDetailCat endpointmediumCVSS 6.5
- CVE-2026-90488: Xuxueli xxl-job remote code execution in Groovy class loadermediumCVSS 6.3EPSS 0.4%
- CVE-2026-7305: Xuxueli xxl-job SSRF in trigger EndpointmediumCVSS 6.3EPSS 0.2%
- CVE-2026-7306: Xuxueli xxl-job hard-coded default token in OpenAPI endpointmediumCVSS 5.6EPSS 0.3%
- CVE-2026-90487: Xuxueli xxl-job privilege escalation in JobGroupControllermediumCVSS 4.3EPSS 0.4%
- CVE-2026-7303: Xuxueli xxl-job IDOR in Execution Log HandlerlowCVSS 3.7EPSS 0.7%
- CVE-2026-90489: Xuxueli xxl-job cross-site scripting in job info insertlowCVSS 3.5EPSS 0.3%
- CVE-2026-52371: XXL-JOB SSRF in jobinfo trigger componentinfoCVSS 0
- CVE-2026-26719: xxl-job xxl-job-admin stored XSS in JobInfoControllerinfoCVSS 0
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/xxl-job.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "XXL-JOB vulnerabilities", https://junglewise.ai/threats/technologies/xxl-job, 26 September 2026.