Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Paypal

First CVE: Jan 13, 2006Active for: 21 yearsTotal CVEs: 25
8.5
VTI Score
Low

PayPal's vulnerability profile spans payment-processing platforms and web-facing applications, including core payment services and the Braintree subsidiary's sanitization libraries, presenting an attack surface concentrated in transaction and developer-tooling layers. Vulnerabilities affecting the vendor recur through input-validation and web-application weakness classes, including improper input validation, cross-site scripting, command injection, and certificate-validation flaws that are characteristic of services handling user input and external integrations. The modest scale of disclosed products masks the downstream reach of its libraries and SDKs across merchant and partner ecosystems, where vulnerabilities can propagate broadly despite their origination in a narrow vendor footprint. Defenders should monitor this vendor's releases for both direct payment-platform deployments and embedded use of its developer libraries; current exploitation, severity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Paypal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2006
20 years ago
Most Recent CVE
Feb 24, 2023
1,246 days ago

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-21129CRITICAL
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order
Jan 31, 20239.832NONO
CVE-2013-7202HIGH
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
Apr 27, 20188.125NONO
CVE-2021-23648MEDIUM
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
Mar 16, 20226.123NONO
CVE-2013-7201HIGH
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
Apr 27, 20187.423NONO
CVE-2017-6217MEDIUM
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
Jul 10, 20196.122NONO
CVE-2012-5784MEDIUM
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and
Nov 4, 20125.822NONO
CVE-2017-6215MEDIUM
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
Aug 2, 20185.420NONO
CVE-2017-6213MEDIUM
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
Aug 2, 20185.420NONO
CVE-2017-6099MEDIUM
Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script o
Feb 24, 20176.120NONO
CVE-2012-5787MEDIUM
The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all
Nov 4, 20125.820NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
84%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (36.0%)
Unknown16 (64.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (28.0%)
High2 (8.0%)
Unknown16 (64.0%)
User Interaction
None3 (12.0%)
Unknown16 (64.0%)
Required6 (24.0%)
Privileges Required
Low2 (8.0%)
High0 (0.0%)
None7 (28.0%)
Unknown16 (64.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Paypal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Paypal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Paypal's Products

View all 4 CNAs →

Top CWEs