Browse all 7 CVE security advisories affecting Paymenter. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-71537 | Paymenter: Credit-refund double-spend race condition in service downgrade (doUpgrade) — Paymenter CWE-362 | 6.5 | Medium | 2026-09-18 |
| CVE-2026-55219 | Paymenter: Race condition in payWithCredit() enables credit double-spend — Paymenter CWE-362 | 5.3 | Medium | 2026-07-20 |
| CVE-2026-47198 | Paymenter: URL parameter injection bypasses paid plan limits at checkout — Paymenter CWE-20 | 8.5 | High | 2026-07-20 |
| CVE-2026-44585 | Paymenter: Broken object level authorization via service reference manipulation on ticket creation — Paymenter CWE-639 | 5.4 | Medium | 2026-07-20 |
| CVE-2026-44583 | Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module — Paymenter CWE-918 | 5.3 | Medium | 2026-07-20 |
| CVE-2026-44584 | Paymenter doesn't reset email verification status after email change — Paymenter CWE-345 | 4.3 | Medium | 2026-07-20 |
| CVE-2025-58048 | Paymenter Vulnerable to Remote Code Execution via Public File Uploads — Paymenter CWE-434 | 10.0 | Critical | 2025-08-28 |
This page lists every published CVE security advisory associated with Paymenter. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.