VulnSea

paymenter/paymenter vulnerabilities

CVEs whose affected-version data names the paymenter/paymenter package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-71537Medium· 6.5
4d ago

Paymenter is a free and open-source webshop solution for management of hosting services

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…

Sunlitpaymenter · paymenter/paymenterEPSS 0.23%via NVD
CVE-2026-55219Medium· 5.3
2mo ago

Paymenter has race condition in payWithCredit() that enables credit double-spend

Paymenter has race condition in payWithCredit() that enables credit double-spend

Sunlitpaymenter · paymenter/paymenterEPSS 0.21%via GHSA
CVE-2026-47198High· 8.5
2mo ago

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Twilightpaymenter · paymenter/paymenterEPSS 0.40%via GHSA
CVE-2025-58048Critical· 9.9
3mo ago

Paymenter vulnerable to Remote Code Execution via public file uploads

Paymenter vulnerable to Remote Code Execution via public file uploads

Midnightpaymenter · paymenter/paymenterEPSS 0.41%via GHSA
CVE-2026-44583Medium· 5.3
3mo ago

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module

Sunlitpaymenter · paymenter/paymenterEPSS 0.41%via GHSA
CVE-2026-44584Medium· 4.3
3mo ago

Paymenter doesn't reset email verification status after email change

Paymenter doesn't reset email verification status after email change

Sunlitpaymenter · paymenter/paymenterEPSS 0.16%via GHSA
CVE-2026-44585Medium· 5.4
3mo ago

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Sunlitpaymenter · paymenter/paymenterEPSS 0.29%via GHSA
paymenter/paymenter vulnerabilities (CVEs) · VulnSea