chaskiq
by chaskiq
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-72536 | Hig | 0.56 | 8.6 | 0.00 | Aug 11, 2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe… | ||
| CVE-2026-72535 | Hig | 0.56 | 8.6 | 0.00 | Aug 11, 2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks… | ||
| CVE-2021-3857 | Med | 0.00 | 5.4 | 0.01 | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3853 | Med | 0.00 | 6.1 | 0.01 | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- risk 0.56cvss 8.6epss 0.00
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe…
- risk 0.56cvss 8.6epss 0.00
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks…
- risk 0.00cvss 5.4epss 0.01
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 6.1epss 0.01
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')