Almapay's vulnerability footprint centers on its Alma payment-processing product, with the observed exposure characterized by input-handling flaws in web-facing components, particularly cross-site scripting weaknesses. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Almapay over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50369MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alma Alma – Pay in installments or later for WooCommerce allows Stored XSS.Thi | Dec 14, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Almapay.
Media articles that mention a CVE ID that affects a product developed by Almapay — matched by CVE ID, not by vendor name.