{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-94145","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-20T20:26:44.174Z","datePublished":"2026-09-21T06:45:09.385Z","dateUpdated":"2026-09-21T15:39:10.289Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-09-21T06:45:09.385Z"},"title":"xuxueli xxl-job Task Management JobInfoController.java cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"xuxueli","product":"xxl-job","versions":[{"version":"3.0","status":"affected"},{"version":"3.1","status":"affected"},{"version":"3.2","status":"affected"},{"version":"3.3","status":"affected"},{"version":"3.4","status":"affected"},{"version":"3.4.0","status":"affected"},{"version":"3.4.1","status":"affected"},{"version":"3.4.2","status":"affected"},{"version":"3.5.0","status":"affected"}],"cpes":["cpe:2.3:a:xuxueli:xxl-job:*:*:*:*:*:*:*:*"],"modules":["Task Management Interface"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-09-20T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-20T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-20T22:31:52.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"hhhha (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/408060","name":"VDB-408060 | xuxueli xxl-job Task Management JobInfoController.java cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/408060/cti","name":"VDB-408060 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-94145","name":"CVE-2026-94145 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/893853","name":"Submit #893853 | https://github.com/xuxueli/xxl-job xxl-job <=3.5.0 Stored Cross-Site Scripting Attack","tags":["third-party-advisory"]},{"url":"https://github.com/hhhh333/CVE/blob/main/xxl-job-xss%202.md","tags":["exploit"]}],"x_generator":["VulDB PVTS v202609"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-21T15:38:21.593357Z","id":"CVE-2026-94145","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-21T15:39:10.289Z"}}]}}