Skip to content
Cross-Site Scripting Vulnerabilities Disclosed for xuxueli and Xerox Products

Cross-Site Scripting Vulnerabilities Disclosed for xuxueli and Xerox Products

First seen 23 Sep 2026, 09:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 09:58 UTC

Two vulnerabilities have been disclosed affecting different software products. CVE-2026-94426 is a low severity cross-site scripting vulnerability in xuxueli xxl-job up to version 3.5.0, allowing remote exploitation through an unknown function in the file /jobgroup/insert. The vendor did not respond to disclosure attempts. CVE-2026-1769 is a medium severity stored cross-site scripting vulnerability in Xerox CentreWare Web, affecting versions up to 7.0.6, which was responsibly disclosed by a researcher. The CVSS score for CVE-2026-94426 is 3.5, while CVE-2026-1769 has a score of 5.3. No public exploit code exists for CVE-2026-94426, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Organizations are advised to apply patches and monitor their systems for potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-02-06
CVE-2026-1769 published
Stored cross-site scripting vulnerability in Xerox CentreWare Web disclosed to the public.
Sploitus
2026-09-21
CVE-2026-94426 publicly disclosed
Low severity cross-site scripting vulnerability in xuxueli xxl-job was disclosed without vendor response.
Thehackerwire
Recent
Patching recommended for affected systems
Organizations are advised to apply the latest security patches and monitor for exploitation attempts.
Thehackerwire

More articles in this cluster (4)

Following this threat?

Track Xerox and CVE-2026-1769 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed