Sploitus Cross-Site Scripting Vulnerabilities Disclosed for xuxueli and Xerox Products
Article Content
- •CVE-2026-94426 is a low severity cross-site scripting vulnerability in xuxueli xxl-job.
- •CVE-2026-1769 is a medium severity stored cross-site scripting vulnerability in Xerox CentreWare Web.
- •Organizations should apply patches and monitor for signs of exploitation.
Two vulnerabilities have been disclosed affecting different software products. CVE-2026-94426 is a low severity cross-site scripting vulnerability in xuxueli xxl-job up to version 3.5.0, allowing remote exploitation through an unknown function in the file /jobgroup/insert. The vendor did not respond to disclosure attempts. CVE-2026-1769 is a medium severity stored cross-site scripting vulnerability in Xerox CentreWare Web, affecting versions up to 7.0.6, which was responsibly disclosed by a researcher. The CVSS score for CVE-2026-94426 is 3.5, while CVE-2026-1769 has a score of 5.3. No public exploit code exists for CVE-2026-94426, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Organizations are advised to apply patches and monitor their systems for potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Xerox and CVE-2026-1769 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…