Home/Product/btcpayserver btcpay server
Product

btcpayserver btcpay server

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-1270
< 1.8.3
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
5.4MEDIUM
CVE-2023-1149
< 1.8.0
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
5.4MEDIUM
CVE-2023-0879
< 1.7.12
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
6.3MEDIUM
CVE-2023-0810
< 1.7.11
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
5.4MEDIUM
CVE-2023-0748
< 1.7.6
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
6.4MEDIUM
CVE-2023-0747
< 1.7.6
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
5.5MEDIUM
CVE-2022-32984
>= 1.3.0 and <= 1.5.3
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is expo
7.5HIGH
CVE-2023-0493
< 1.7.5
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
5.3MEDIUM
CVE-2021-3830
<= 1.2.3
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
5.4MEDIUM
CVE-2021-3646
< 1.2.3
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
6.1MEDIUM
CVE-2021-29250
<= 1.0.7.0
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functiona
5.4MEDIUM
CVE-2021-29248
<= 1.0.7.0
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure f
5.3MEDIUM
CVE-2021-29247
<= 1.0.7.0
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly
5.3MEDIUM
CVE-2021-29246
<= 1.0.7.0
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code exe
6.7MEDIUM
CVE-2021-29245
<= 1.0.7.0
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
5.3MEDIUM
CVE-2021-29251
< 1.0.7.1
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affec
6.5MEDIUM
CVE-2021-29249
< 1.0.6.0
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin