Pay
This hub aggregates every CVE we track for Pay, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesmobile app
6
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3LOW2MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
1
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Pay.
- CVE-2026-70658pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier7.4
- CVE-2026-33661WeChat Pay callback signature verification bypassed when Host header is localhost8.6
- CVE-2023-30614Improper Neutralization of Script-Related HTML Tags in a Web Page in pay7.1
- CVE-2022-35917Weakness in Transfer Validation Logic in @solana/pay5.3
- CVE-2021-25527Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.3.8
- CVE-2021-25525Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.2.0
Product normalization is registry-driven with AI assist and human review. How it works