Phonepe is a financial payments and digital wallet platform whose vulnerability profile concentrates in its core application, with recurring issues centered on sensitive-data handling including cleartext storage, improper exposure of authentication and transactional information, and server-side request forgery that can circumvent internal service boundaries. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility and business-logic appeal of payment applications to security researchers and adversaries. Defenders should prioritize patches affecting this vendor's mobile and backend services and audit data-storage practices; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phonepe over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45835HIGH Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15. | Nov 13, 2023 | 7.5 | 54 | NO | YES |
CVE-2018-17401HIGH The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password fe | Sep 23, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-17403HIGH The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to impersonate a user and set up their account without their knowledge. | Sep 23, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-17400HIGH The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by intercepting the user name and PI | Sep 23, 2018 | 7.0 | 23 | NO | NO |
CVE-2018-17402MEDIUM The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number, expiration date, and CVV numbe | Sep 23, 2018 | 5.3 | 20 | NO | NO |
CVE-2025-5154MEDIUM A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databas | May 25, 2025 | 4.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phonepe.
Media articles that mention a CVE ID that affects a product developed by Phonepe — matched by CVE ID, not by vendor name.