Paytm operates a payment gateway platform whose vulnerability profile centers on application-layer input-handling issues, specifically SQL injection and server-side request forgery flaws that are characteristic of web-based payment processing systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paytm over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45362MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0. | Dec 7, 2023 | 6.5 | 50 | NO | YES |
CVE-2022-45805CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue aff | Nov 3, 2023 | 9.8 | 39 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paytm.
Media articles that mention a CVE ID that affects a product developed by Paytm — matched by CVE ID, not by vendor name.