Browse all 3 CVE security advisories affecting Jexactyl. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-107854 | Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing ownership check) — Jexactyl CWE-639 | 5.4 | Medium | 2026-10-09 |
| CVE-2026-107852 | Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as full payment (payment forgery) — Jexactyl CWE-345 | 7.1 | High | 2026-10-09 |
| CVE-2026-33061 | Jexactyl has Stored DOM Cross-Site Scripting (XSS) via unescaped JSON in Blade template — Jexactyl CWE-79 | 5.8 | Medium | 2026-03-20 |
This page lists every published CVE security advisory associated with Jexactyl. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.