Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Btcpayserver MEDIUM 5.4
CVE-2023-1270

Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.

Fix: 1.8.3+
Fix from $1,600 2023-03-08
Btcpay Server MEDIUM 5.4
CVE-2023-1149

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.

Fix: 1.8.0+
Fix from $1,600 2023-03-02
Btcpay Server MEDIUM 5.4
CVE-2023-0879

Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.

Fix: 1.7.12+
Fix from $1,600 2023-02-17
Btcpayserver MEDIUM 5.4
CVE-2023-0810

Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.

Fix: 1.7.11+
Fix from $1,600 2023-02-13
Btcpayserver MEDIUM 6.1
CVE-2023-0748

Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

Fix: 1.7.6+
Fix from $1,600 2023-02-08
Btcpayserver MEDIUM 5.4
CVE-2023-0747

Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

Fix: 1.7.6+
Fix from $1,600 2023-02-08
Btcpay Server HIGH 7.5
CVE-2022-32984

BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive …

Fix: after 1.5.3
Fix from $1,950 2023-01-31
Btcpay Server HIGH 8.8
CVE-2023-0493EPSS 8%

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.

Fix: 1.7.5+
Fix from $1,950 2023-01-26
Btcpay Server MEDIUM 5.4
CVE-2021-3830

btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: after 1.2.3
Fix from $1,600 2021-09-26
Btcpay Server MEDIUM 6.1
CVE-2021-3646

btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 1.2.3+
Fix from $1,600 2021-09-10
Btcpay Server MEDIUM 6.7
CVE-2021-29246

BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacke…

Fix: after 1.0.7.0
Fix from $1,600 2021-05-05
Btcpay Server MEDIUM 5.4
CVE-2021-29250

BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables …

Fix: after 1.0.7.0
Fix from $1,600 2021-05-05
Btcpay Server MEDIUM 5.3
CVE-2021-29245

BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.

Fix: after 1.0.7.0
Fix from $1,600 2021-05-05
Btcpay Server MEDIUM 5.3
CVE-2021-29247

BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.

Fix: after 1.0.7.0
Fix from $1,600 2021-05-05
Btcpay Server MEDIUM 5.3
CVE-2021-29248

BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.

Fix: after 1.0.7.0
Fix from $1,600 2021-05-05
Btcpay Server MEDIUM 6.5
CVE-2021-29251

BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases…

Fix: 1.0.7.1+
Fix from $1,600 2021-04-01
Btcpay Server HIGH 7.5
CVE-2021-29249

BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.

Fix: 1.0.6.0+
Fix from $1,950 2021-03-26