Btcpay Server

Vendor:

First CVE: Mar 26, 2021 · Active for 5 years

17
Total CVEs
More Total CVEs than 92% of tracked products
8.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Btcpay Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2021
5 years ago
Most Recent CVE
Mar 8, 2023
1,238 days ago

CVE Severity & Scoring

Btcpay Server17 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (47.1%)
Unknown0 (0.0%)
Required9 (52.9%)
Privileges Required
Low9 (52.9%)
High1 (5.9%)
None7 (41.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
Jan 26, 20238.841NOYES
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML
Jan 31, 20237.525NONO
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
Mar 26, 20217.524NONO
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Sep 10, 20216.122NONO
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin
May 5, 20216.722NONO
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is conf
Apr 1, 20216.522NONO
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
Feb 8, 20236.121NONO
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
Mar 8, 20235.420NONO
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
Mar 2, 20235.420NONO
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
Feb 17, 20235.420NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Btcpay Server

Top CWEs

Versions

No cataloged versions.