CVE Tools

Jumpserver

7 CVEs tracked since 2023. Since Sep 2023, none of them reached CISA KEV.

Jumpserver CVEs per month

Sep 2023 to Sep 2023. Point at a month, or focus the strip and use the arrow keys.
Jumpserver CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0970

Products

The products that kept showing up in Jumpserver's monthly top three, with their CVEs summed over those months.

  1. Jumpserver71 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Jumpserver.

  1. CVE-2026-44846JumpServer: Privilege Overwrite via Organization Invite Logic Flaw6.2
  2. CVE-2026-44845JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host Deployment6.7
  3. CVE-2026-54336JumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized Asset5.4
  4. CVE-2026-31864JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering6.8
  5. CVE-2026-31798JumpServer Improper Certificate Validation in Custom SMS API Client5.0
  6. CVE-2025-58044JumpServer has an Open Redirect Vulnerability6.1
  7. CVE-2025-62795JumpServer Unauthorized LDAP Configuration Access via WebSocket7.1
  8. CVE-2025-62712JumpServer Connection Token Leak Vulnerability9.6
  9. CVE-2025-27095JumpServer has a Kubernetes Token Leak Vulnerability4.3
  10. CVE-2024-40628Arbitrary File Read in Ansible Playbooks in Jumpserver10.0
  11. CVE-2024-40629Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserver10.0
  12. CVE-2024-29202JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery9.9
  13. CVE-2024-29201JumpServer's insecure Ansible playbook validation leads to RCE in Celery9.9
  14. CVE-2024-29020JumpServer allows nn authorized attacker to get sensitive information in playbook files when playbook_id is leaked4.6
  15. CVE-2024-29024JumpServer Direct Object Reference (IDOR) Vulnerability in File Manager Bulk Transfer Functionality4.6

The record

Peak rank
#90 in Sep 2023
Busiest month shown
Sep 2023, 7 CVEs
Months with a KEV entry
0 since Sep 2023
Monthly snapshots
1 since 2023
Jumpserver's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store