CVE-2026-107854
- EPSS -
- Veröffentlicht 09.10.2026 20:31:02
- Zuletzt bearbeitet 09.10.2026 21:17:03
Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned...
CVE-2026-107852
- EPSS -
- Veröffentlicht 09.10.2026 20:28:06
- Zuletzt bearbeitet 09.10.2026 21:17:03
Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total ...
CVE-2026-33061
- EPSS 0.17%
- Veröffentlicht 20.03.2026 07:34:14
- Zuletzt bearbeitet 14.04.2026 17:56:38
Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80efab628d1241198ea4f079779cfd inject server-side objects into client-side JavaScript through resources/v...