VYPR
Vendor

Paymenter

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2025-58048CriAug 28, 2025
    risk 0.57cvss 9.9epss 0.00

    Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive data extraction from the database,…

  • CVE-2026-71537MedSep 18, 2026
    risk 0.35cvss 6.5epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later executes $credit->increment('amount',…

  • CVE-2026-55219MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction.…

  • CVE-2026-47198HigJul 20, 2026
    risk 0.00cvss 8.5epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning…