VYPR
Vendor

Paypal

Products
31
CVEs
29
Across products
37
Status
Private

Products

31
View all 31 products →

Recent CVEs

29
View all 29 CVEs →
  • CVE-2013-7202HigApr 27, 2018
    risk 0.53cvss 8.1epss 0.02

    The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.

  • CVE-2013-7201HigApr 27, 2018
    risk 0.48cvss 7.4epss 0.02

    WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

  • CVE-2021-47885MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute…

  • CVE-2024-41670HigJul 26, 2024
    risk 0.42cvss 7.5epss 0.00

    In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment…

  • CVE-2022-21129HigJan 31, 2023
    risk 0.41cvss 7.4epss 0.03

    Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium…

  • CVE-2017-6217MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution

  • CVE-2017-6099MedFeb 24, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.

  • CVE-2017-6213MedAug 2, 2018
    risk 0.35cvss 5.4epss 0.01

    paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.

  • CVE-2022-48345MedFeb 24, 2023
    risk 0.33cvss 6.1epss 0.01

    sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

  • CVE-2017-6215MedAug 2, 2018
    risk 0.28cvss 5.4epss 0.01

    paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.

  • CVE-2008-6535Mar 26, 2009
    risk 0.04cvss epss 0.06

    admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter.

  • CVE-2021-23648MedMar 16, 2022
    risk 0.00cvss 5.4epss 0.01

    The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.

  • CVE-2011-5237Nov 6, 2012
    risk 0.00cvss epss 0.01

    PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2012-5806Nov 4, 2012
    risk 0.00cvss epss 0.01

    The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…

  • CVE-2012-5805Nov 4, 2012
    risk 0.00cvss epss 0.01

    The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…

  • CVE-2012-5802Nov 4, 2012
    risk 0.00cvss epss 0.01

    The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2012-5798Nov 4, 2012
    risk 0.00cvss epss 0.01

    The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…

  • CVE-2012-5796Nov 4, 2012
    risk 0.00cvss epss 0.01

    The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2012-5791Nov 4, 2012
    risk 0.00cvss epss 0.01

    PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2012-5790Nov 4, 2012
    risk 0.00cvss epss 0.01

    PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…