Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Adaptive Payments Sdk MEDIUM 6.1
CVE-2017-6217

paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution

No fix yet
Fix from $1,600 2019-07-10
Merchant Sdk Php MEDIUM 6.1
CVE-2017-6099

Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers t…

No fix yet
Fix from $1,600 2017-02-24
Wps Toolkit MEDIUM 5.8
CVE-2011-5237

PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.…

Mitigation only
Fix from $1,600 2012-11-06
Paypal MEDIUM 5.8
CVE-2012-5802

The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fiel…

No fix yet
Fix from $1,600 2012-11-04
Instant Payment Notification MEDIUM 5.8
CVE-2012-5805

The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectA…

No fix yet
Fix from $1,600 2012-11-04
Payments Pro MEDIUM 5.8
CVE-2012-5806

The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjec…

No fix yet
Fix from $1,600 2012-11-04
Ipn MEDIUM 5.8
CVE-2012-5788

The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

No fix yet
Fix from $1,600 2012-11-04
Payments Standard MEDIUM 5.8
CVE-2012-5789

PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)…

No fix yet
Fix from $1,600 2012-11-04
Payments Standard MEDIUM 5.8
CVE-2012-5790

PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub…

No fix yet
Fix from $1,600 2012-11-04
Invoicing MEDIUM 5.8
CVE-2012-5791

PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50…

No fix yet
Fix from $1,600 2012-11-04
Ubercart Payflow MEDIUM 5.0
CVE-2012-2058

The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

Mitigation only
Fix from $1,600 2012-09-17