Skip to main content

Vendor archive

paypal CVEs

Beta · best-effort

25 CVEs tagged to vendor paypal0 Critical, 3 High, 21 Medium, 1 Low, 0 Unrated.

CVE-2022-21129

Published Jan 31, 2023

Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In orde…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6217

Published Jul 10, 2019

paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6215

Published Aug 2, 2018

paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6213

Published Aug 2, 2018

paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7202

Published Apr 27, 2018

The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7201

Published Apr 27, 2018

WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6099

Published Feb 24, 2017

Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5237

Published Nov 6, 2012

PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5806

Published Nov 4, 2012

The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 ce…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5802

Published Nov 4, 2012

The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, wh…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5796

Published Nov 4, 2012

The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5791

Published Nov 4, 2012

PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows ma…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5790

Published Nov 4, 2012

PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5789

Published Nov 4, 2012

PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5788

Published Nov 4, 2012

The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5787

Published Nov 4, 2012

The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which al…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0201

Published Jan 13, 2006

Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0202

Published Jan 13, 2006

Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1