CVE-2026-44584Medium· 4.3▾ SunlitPaymenter doesn't reset email verification status after email change
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
The email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain its verified status after switching to an unverified or unowned email address.
When a user updated their email address, the system did not reset or revalidate the associated email verification status. As a result, the verification column remained set to “true” even after the email address was changed.
This allowed an attacker to:
No verification challenge or confirmation was required for the newly assigned email address.
This vulnerability allows a user to associate a verified account with an email address they do not control, this may result in:
No direct unauthorized access to other users accounts or data is possible through this issue alone.
paymenter/paymenter < 1.5.0Upgrade to a patched release:
paymenter/paymenter 1.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71537Medium· 6.5Paymenter is a free and open-source webshop solution for management of hosting services
CVE-2026-55219Medium· 5.3Paymenter has race condition in payWithCredit() that enables credit double-spend
CVE-2026-47198High· 8.5Paymenter has URL parameter injection that bypasses paid plan limits at checkout
CVE-2025-58048Critical· 9.9Paymenter vulnerable to Remote Code Execution via public file uploads
CVE-2026-44583Medium· 5.3Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
CVE-2026-44585Medium· 5.4Paymenter has broken object level authorization via service reference manipulation on ticket creation