CVE-2026-107852None▾ SunlitJexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the referenced order and configured billing currency. On an instance where the billing module is enabled and a Stripe secret key is configured, an authenticated client can therefore complete a lower-value or mismatched-currency payment and cause the order to be processed, provisioning, renewing, upgrading, or unsuspending the purchased server for less than the required price. This issue is fixed in version 4.0.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-31356NoneInsufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure
CVE-2026-62367HighVikunja is an open-source self-hosted task management platform
CVE-2023-51764Medium· 5.3Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions)
CVE-2026-82858Critical· 9.8@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted
CVE-2026-13257Medium· 6.5IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authent…
CVE-2026-103517Medium· 5.3The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated att…