SecAlerts
p

paypal

Security Risk Profile

37
/100
low

Security Risk Score

Comprehensive risk assessment based on 41 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 13, 2006 to present

41
Total CVEs
5
Critical+High
1
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
37/100
low
⚠️ 1 Active Exploits📈 2 in Last 30 Days

Severity Distribution

Critical
1
High
4
Medium
30
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Input Validation
12
2
XSS
10
3
CSRF
2
4
SQL Injection
1
5
Command Injection
1

Most Affected Products

1. Apache Axis25
2. Paypal PayPal6
3. IBM Data Virtualization on Cloud Pak for Data6
4. IBM Watson Query on Cloud Pak for Data6
5. osCommerce Online Merchant4

Recent Vulnerabilities

See more →
CVE-2026-16990
CVSS 5.3medium

Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation

Aug 12, 2026🔧 No Patch
CVE-2026-13399
CVSS 7.5high

Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order

Aug 6, 2026🔧 No Patch
CVE-2026-15502
CVSS 5.3medium

AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection

Jul 12, 2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1u9d9kn/authenticating_a_paypal_notification_is_not_the/
unknown

Authenticating a PayPal notification is not the same as trusting what it says (CVE-2026-9189)

Jun 18, 2026🔧 No Patch
CVE-2025-12752
CVSS 5.3medium

Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation

Nov 22, 2025🔧 No Patch
CVE-2025-11859
CVSS 6.4medium

Paypal Donation Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 11, 2025🔧 No Patch
CVE-2025-10309
CVSS 4.3medium

PayPal Forms <= 1.0.3 - Cross-Site Request Forgery

Oct 3, 2025🔧 No Patch
https://www.theregister.com/2025/08/28/euro_banks_block_paypal_direct_debits/
unknown

Euro banks block billions in rogue PayPal direct debits after fraud glitch

Aug 28, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/phishers-abuse-google-oauth-to-spoof-google-in-dkim-replay-attack/
unknown

Phishers abuse Google OAuth to spoof Google in DKIM replay attack

Apr 20, 2025🔧 No Patch
CVE-2024-13560
CVSS 4.3medium

Subscriptions & Memberships for PayPal <= 1.1.6 - Cross-Site Request Forgery to Arbitrary Post Deletion

Feb 26, 2025🔧 No Patch

Monitor paypal in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.