Openwaygroup's vulnerability footprint centers on the Way4 payment and banking platform, a niche but strategically important product deployed in financial-services environments. The recurring exposure involves web-application layer issues, including sensitive-information disclosure in error messages and cross-site scripting weaknesses, that are characteristic of complex transaction-processing systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openwaygroup over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35059MEDIUM OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter. | Oct 11, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-35060MEDIUM /way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stor | Oct 11, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openwaygroup.
Media articles that mention a CVE ID that affects a product developed by Openwaygroup — matched by CVE ID, not by vendor name.