VYPR

Jexactyl

by Jexactyl

Source repositories

CVEs (3)

  • CVE-2026-107852HigOct 9, 2026
    risk 0.39cvss —epss —

    Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the…

  • CVE-2026-33061MedMar 20, 2026
    risk 0.31cvss 5.8epss 0.00

    Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af58da and before e28edb204e80efab628d1241198ea4f079779cfd inject server-side objects into client-side JavaScript through resources/views/templates/wrapper.blade.p…

  • CVE-2026-107854MedOct 9, 2026
    risk 0.28cvss 5.4epss —

    Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated…