Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-1270 Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3. Btcpayserver 1.8.3+ Fix from $1,6002023-03-08 MEDIUM 5.4 CVE-2023-1149 Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0. Btcpay Server 1.8.0+ Fix from $1,6002023-03-02 MEDIUM 5.4 CVE-2023-0879 Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12. Btcpay Server 1.7.12+ Fix from $1,6002023-02-17 MEDIUM 5.4 CVE-2023-0810 Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11. Btcpayserver 1.7.11+ Fix from $1,6002023-02-13 MEDIUM 6.1 CVE-2023-0748 Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. Btcpayserver 1.7.6+ Fix from $1,6002023-02-08 MEDIUM 5.4 CVE-2023-0747 Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6. Btcpayserver 1.7.6+ Fix from $1,6002023-02-08 HIGH 7.5 CVE-2022-32984 BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive … Btcpay Server after 1.5.3 Fix from $1,9502023-01-31 HIGH 8.8 CVE-2023-0493EPSS 8% Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5. Btcpay Server 1.7.5+ Fix from $1,9502023-01-26 MEDIUM 5.4 CVE-2021-3830 btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Btcpay Server after 1.2.3 Fix from $1,6002021-09-26 MEDIUM 6.1 CVE-2021-3646 btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Btcpay Server 1.2.3+ Fix from $1,6002021-09-10 MEDIUM 6.7 CVE-2021-29246 BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacke… Btcpay Server after 1.0.7.0 Fix from $1,6002021-05-05 MEDIUM 5.4 CVE-2021-29250 BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables … Btcpay Server after 1.0.7.0 Fix from $1,6002021-05-05 MEDIUM 5.3 CVE-2021-29245 BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key. Btcpay Server after 1.0.7.0 Fix from $1,6002021-05-05 MEDIUM 5.3 CVE-2021-29247 BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie. Btcpay Server after 1.0.7.0 Fix from $1,6002021-05-05 MEDIUM 5.3 CVE-2021-29248 BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie. Btcpay Server after 1.0.7.0 Fix from $1,6002021-05-05 MEDIUM 6.5 CVE-2021-29251 BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases… Btcpay Server 1.0.7.1+ Fix from $1,6002021-04-01 HIGH 7.5 CVE-2021-29249 BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability. Btcpay Server 1.0.6.0+ Fix from $1,9502021-03-26