Cardgate operates a payment-processing platform focused on merchant integration and transaction handling, representing a niche but integral component of e-commerce infrastructure. The vendor's durable signal centers on its payments product and recurs through origin-validation weaknesses, reflecting the access-control and third-party-integration demands of payment gateways. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cardgate over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8819HIGH An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.p | Feb 25, 2020 | 8.1 | 31 | NO | YES |
CVE-2020-8818HIGH An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Ca | Feb 25, 2020 | 8.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cardgate.
Media articles that mention a CVE ID that affects a product developed by Cardgate — matched by CVE ID, not by vendor name.