PayPal's vulnerability profile spans payment-processing platforms and web-facing applications, including core payment services and the Braintree subsidiary's sanitization libraries, presenting an attack surface concentrated in transaction and developer-tooling layers. Vulnerabilities affecting the vendor recur through input-validation and web-application weakness classes, including improper input validation, cross-site scripting, command injection, and certificate-validation flaws that are characteristic of services handling user input and external integrations. The modest scale of disclosed products masks the downstream reach of its libraries and SDKs across merchant and partner ecosystems, where vulnerabilities can propagate broadly despite their origination in a narrow vendor footprint. Defenders should monitor this vendor's releases for both direct payment-platform deployments and embedded use of its developer libraries; current exploitation, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paypal over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21129CRITICAL Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function.
**Note:** In order | Jan 31, 2023 | 9.8 | 32 | NO | NO |
CVE-2013-7202HIGH The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system. | Apr 27, 2018 | 8.1 | 25 | NO | NO |
CVE-2021-23648MEDIUM The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. | Mar 16, 2022 | 6.1 | 23 | NO | NO |
CVE-2013-7201HIGH WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information. | Apr 27, 2018 | 7.4 | 23 | NO | NO |
CVE-2017-6217MEDIUM paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution | Jul 10, 2019 | 6.1 | 22 | NO | NO |
CVE-2012-5784MEDIUM Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and | Nov 4, 2012 | 5.8 | 22 | NO | NO |
CVE-2017-6215MEDIUM paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution. | Aug 2, 2018 | 5.4 | 20 | NO | NO |
CVE-2017-6213MEDIUM paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution. | Aug 2, 2018 | 5.4 | 20 | NO | NO |
CVE-2017-6099MEDIUM Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script o | Feb 24, 2017 | 6.1 | 20 | NO | NO |
CVE-2012-5787MEDIUM The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all | Nov 4, 2012 | 5.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paypal.
Media articles that mention a CVE ID that affects a product developed by Paypal — matched by CVE ID, not by vendor name.