Compassplus maintains a specialized portfolio of payment-processing and financial-institution systems, including its Tranzware e-commerce gateway and online banking interfaces. Vulnerabilities affecting these products concentrate on web-tier input-handling and output-encoding issues, particularly cross-site scripting and XML external entity injection, which are characteristic of web-facing financial software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Compassplus over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28110HIGH /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. | Mar 19, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-43106MEDIUM A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be man | Feb 14, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-28126MEDIUM index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability | Mar 19, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-28109MEDIUM TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS). | Mar 19, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Compassplus.
Media articles that mention a CVE ID that affects a product developed by Compassplus — matched by CVE ID, not by vendor name.