Jupiter X Core <= 4.14.1 - Missing Authorization
Jupiter X Core
Minimum safe version
4.14.2
Update to 4.14.2 or later to address 25 fixable vulnerabilities
CVE-2025-58264
Jupiter X Core <= 4.14.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import
CVE-2025-50004
Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG
CVE-2025-47475
Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR
Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)
Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read
CVE-2024-12033
CVE-2024-12316
CVE-2024-7772
CVE-2024-7781
CVE-2023-38389
CVE-2023-38388
CVE-2023-38385
CVE-2023-38394
CVE-2023-3813
Jupiter X Core <= 2.0.9 - Missing Authorization Checks
CVE-2022-1657
CVE-2022-1654
CVE-2022-1658
CVE-2022-1659
CVE-2022-1656