Bpcbt's vulnerability profile centers on the SmartVista payment-processing platform and its associated front-end and card-generation components, which handle sensitive transactional workflows. The recurring weakness classes—SQL injection, path traversal, cross-site scripting, cross-site request forgery, and improper privilege management—reflect input-validation and access-control challenges endemic to web-based financial applications, with a meaningful share reaching serious severity. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bpcbt over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38619CRITICAL SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf. | Sep 21, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-38617HIGH SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf. | Sep 19, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-38616HIGH SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf. | Sep 13, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-38615HIGH SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/f | Sep 9, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-38618HIGH SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/ | Sep 19, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-38614HIGH An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter. | Sep 9, 2022 | 7.5 | 27 | NO | NO |
CVE-2018-15206HIGH BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf. | Apr 30, 2019 | 8.8 | 27 | NO | NO |
CVE-2022-38613MEDIUM A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system. | Sep 9, 2022 | 6.5 | 24 | NO | NO |
CVE-2022-35554MEDIUM Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an attacker to execute javascript code at client side. | Aug 19, 2022 | 6.1 | 23 | NO | NO |
CVE-2018-15208HIGH BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter. | Apr 30, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bpcbt.
Media articles that mention a CVE ID that affects a product developed by Bpcbt — matched by CVE ID, not by vendor name.