Payhere operates a payment-processing platform with a narrowly scoped product portfolio centered on its payment gateway service. The observed vulnerabilities reflect information-disclosure risks associated with logging and data-handling practices in payment systems, where sensitive data exposure carries inherent compliance and customer trust implications. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Payhere over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6064HIGH The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur. | Jan 1, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Payhere.
Media articles that mention a CVE ID that affects a product developed by Payhere — matched by CVE ID, not by vendor name.