Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bpcbt

First CVE: Apr 30, 2019Active for: 7 yearsTotal CVEs: 11
40.6
VTI Score
High

Bpcbt's vulnerability profile centers on the SmartVista payment-processing platform and its associated front-end and card-generation components, which handle sensitive transactional workflows. The recurring weakness classes—SQL injection, path traversal, cross-site scripting, cross-site request forgery, and improper privilege management—reflect input-validation and access-control challenges endemic to web-based financial applications, with a meaningful share reaching serious severity. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bpcbt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2019
7 years ago
Most Recent CVE
Sep 21, 2022
1,402 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-38619CRITICAL
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
Sep 21, 20229.833NONO
CVE-2022-38617HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
Sep 19, 20228.830NONO
CVE-2022-38616HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
Sep 13, 20228.830NONO
CVE-2022-38615HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/f
Sep 9, 20228.830NONO
CVE-2022-38618HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/
Sep 19, 20228.829NONO
CVE-2022-38614HIGH
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
Sep 9, 20227.527NONO
CVE-2018-15206HIGH
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
Apr 30, 20198.827NONO
CVE-2022-38613MEDIUM
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
Sep 9, 20226.524NONO
CVE-2022-35554MEDIUM
Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side.
Aug 19, 20226.123NONO
CVE-2018-15208HIGH
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
Apr 30, 20197.523NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
18%
73%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low5 (45.5%)
High1 (9.1%)
None5 (45.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bpcbt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bpcbt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bpcbt's Products

View all 1 CNAs →

Top CWEs