CVE-2026-90489 | Xuxueli xxl-job up to 3.5.0 /jobinfo/insert name/author cross site scripting
A vulnerability, which was classified as problematic, was found in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting.
This vulnerability is documented as CVE-2026-90489. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More