VYPR

PayRange

by PayRange

CVEs (2)

  • CVE-2026-13462Jul 9, 2026
    risk 0.00cvss epss 0.00

    PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.

  • CVE-2026-13461Jul 9, 2026
    risk 0.00cvss epss 0.00

    When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the…