Vulnerabilities
Vulnerable Software
Btcpayserver:  Security Vulnerabilities
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
CVSS Score
5.1
EPSS Score
0.001
Published
2023-03-08
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
CVSS Score
5.7
EPSS Score
0.001
Published
2023-03-02
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
CVSS Score
6.3
EPSS Score
0.001
Published
2023-02-17
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-02-13
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVSS Score
6.4
EPSS Score
0.003
Published
2023-02-08
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVSS Score
5.5
EPSS Score
0.001
Published
2023-02-08
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
CVSS Score
7.5
EPSS Score
0.005
Published
2023-01-31
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
CVSS Score
5.3
EPSS Score
0.014
Published
2023-01-26
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Score
3.8
EPSS Score
0.002
Published
2021-09-26
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Score
4.9
EPSS Score
0.002
Published
2021-09-10


Contact Us

Shodan ® - All rights reserved