Skip to main content

Vendor/product archive

xuxueli / xxl-api CVEs

Beta · best-effort

2 CVEs tagged to xuxueli / xxl-api0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-60646

Published Nov 12, 2025

A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a crafted payload int…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-60645

Published Nov 12, 2025

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1