All 3 CVE vulnerabilities found in Jexactyl, with AI-generated Chinese analysis, references, and POCs.
Vendor: Jexactyl
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-107854 | Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing ownership check) CWE-639 | 5.4 | Medium | 2026-10-09 |
| CVE-2026-107852 | Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as full payment (payment forgery) CWE-345 | 7.1 | High | 2026-10-09 |
| CVE-2026-33061 | Jexactyl has Stored DOM Cross-Site Scripting (XSS) via unescaped JSON in Blade template CWE-79 | 5.8 | Medium | 2026-03-20 |
All 3 known CVE vulnerabilities affecting Jexactyl with full Chinese analysis, references, and POCs where available.