Jumpserver
Vendor:
First CVE: Mar 16, 2023 · Active for 3 years
24
Total CVEs
More Total CVEs than 95% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jumpserver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2023
3 years ago
Most Recent CVE
Mar 13, 2026
133 days ago
CVE Severity & Scoring
Jumpserver24 CVEs
42%
21%
38%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (83.3%)
High4 (16.7%)
Unknown0 (0.0%)
User Interaction
None20 (83.3%)
Unknown0 (0.0%)
Required4 (16.7%)
Privileges Required
Low10 (41.7%)
High1 (4.2%)
None13 (54.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42442MEDIUM JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, sessi | Sep 15, 2023 | 5.3 | 52 | NO | YES |
CVE-2024-29202CRITICAL JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's An | Mar 29, 2024 | 9.9 | 34 | NO | NO |
CVE-2025-58044MEDIUM JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header a | Dec 1, 2025 | 6.1 | 33 | NO | YES |
CVE-2024-29201CRITICAL JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to exe | Mar 29, 2024 | 9.9 | 33 | NO | NO |
CVE-2023-43651CRITICAL JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. Th | Sep 27, 2023 | 9.9 | 31 | NO | NO |
CVE-2024-40629CRITICAL JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remote | Jul 18, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-28110CRITICAL Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. P | Mar 16, 2023 | 9.9 | 29 | NO | NO |
CVE-2025-62712HIGH JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, n | Oct 30, 2025 | 8.1 | 28 | NO | NO |
CVE-2024-40628CRITICAL JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remote | Jul 18, 2024 | 9.1 | 28 | NO | NO |
CVE-2023-43652CRITICAL JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a passwo | Sep 27, 2023 | 9.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Jumpserver
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.8.0 | 1 | 9.8 | 2.0% | 0 | 0 |