paymenter has 7 CVEs on record. Cadence is steady at roughly 3 per quarter. The busiest recent month was June 2026 with 6. The median CVSS is 5.4 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 4
Worst active — by depth score
CVE-2025-58048Critical· 9.9Paymenter vulnerable to Remote Code Execution via public file uploads55CVE-2026-47198High· 8.5Paymenter has URL parameter injection that bypasses paid plan limits at checkout47CVE-2026-71537Medium· 6.5Paymenter is a free and open-source webshop solution for management of hosting services36CVE-2026-44585Medium· 5.4Paymenter has broken object level authorization via service reference manipulation on ticket creation30CVE-2026-55219Medium· 5.3Paymenter has race condition in payWithCredit() that enables credit double-spend29
paymenter vulnerabilities
CVEs affecting paymenter, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-71537Medium· 6.5Paymenter is a free and open-source webshop solution for management of hosting services
Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…
CVE-2026-55219Medium· 5.3Paymenter has race condition in payWithCredit() that enables credit double-spend
Paymenter has race condition in payWithCredit() that enables credit double-spend
CVE-2026-47198High· 8.5Paymenter has URL parameter injection that bypasses paid plan limits at checkout
Paymenter has URL parameter injection that bypasses paid plan limits at checkout
CVE-2025-58048Critical· 9.9Paymenter vulnerable to Remote Code Execution via public file uploads
Paymenter vulnerable to Remote Code Execution via public file uploads
CVE-2026-44583Medium· 5.3Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module
CVE-2026-44584Medium· 4.3Paymenter doesn't reset email verification status after email change
Paymenter doesn't reset email verification status after email change
CVE-2026-44585Medium· 5.4Paymenter has broken object level authorization via service reference manipulation on ticket creation
Paymenter has broken object level authorization via service reference manipulation on ticket creation