VYPR
Vendor

Stripe

Products
8
CVEs
8
Across products
11
Status
Private

Products

8

Recent CVEs

8
  • CVE-2023-23315CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a…

  • CVE-2024-45401HigSep 5, 2024
    risk 0.49cvss 7.5epss 0.00

    stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or…

  • CVE-2021-21420HigApr 1, 2021
    risk 0.49cvss 7.5epss 0.01

    vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary…

  • CVE-2018-19249HigJan 3, 2019
    risk 0.49cvss 7.5epss 0.01

    The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check information if the creation is successful without charging the…

  • CVE-2022-24753HigMar 9, 2022
    risk 0.43cvss 7.7epss 0.00

    Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `stripe login`, `stripe config -e`, `stripe community`, and…

  • CVE-2021-47885MedFeb 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute…

  • CVE-2022-24825MedApr 19, 2022
    risk 0.31cvss 5.8epss 0.01

    Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure.…

  • CVE-2022-29188MedMay 21, 2022
    risk 0.28cvss 5.3epss 0.01

    Smokescreen is an HTTP proxy. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny…