Simpleledger's vulnerability profile centers on a small set of software-validation and wallet-integration tools designed for the Simple Ledger Protocol, a cryptocurrency token layer built on Bitcoin Cash. The recurring exposure spans products such as slp-validate, slpjs, and Electron Cash SLP integrations, with durable weakness classes including incorrect comparison logic, improper input validation, and protocol-parsing gaps that reflect the demands of transaction-validation and cryptographic-state management. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simpleledger over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11071HIGH SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly imple | May 12, 2020 | 8.6 | 27 | NO | NO |
CVE-2020-11014HIGH Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the Electron Cash SLP Edition are at risk of sending the minting | Apr 28, 2020 | 8.6 | 22 | NO | NO |
CVE-2020-11072HIGH In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP | May 12, 2020 | 8.6 | 21 | NO | NO |
CVE-2019-16762MEDIUM A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a | Nov 15, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-16761MEDIUM A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the [email protected] npm package. An attacker co | Nov 15, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-15131HIGH In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorl | Jul 30, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-15130HIGH In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented | Jul 30, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simpleledger.
Media articles that mention a CVE ID that affects a product developed by Simpleledger — matched by CVE ID, not by vendor name.