Stripe's vulnerability profile centers on a modestly represented but high-visibility portfolio spanning its payment-processing platform, command-line tools, and API infrastructure. Its disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including server-side request forgery, authentication bypasses, path traversal, and injection flaws that reflect the authentication, data-handling, and integration demands of a payment-processing platform. Defenders should treat Stripe advisories as priority items given the payment-critical role of affected services; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stripe over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23315CRITICAL The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initConten | Mar 1, 2023 | 9.8 | 24 | NO | NO |
CVE-2022-24753HIGH Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker | Mar 9, 2022 | 7.0 | 24 | NO | NO |
CVE-2021-21420HIGH vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing | Apr 1, 2021 | 7.8 | 24 | NO | NO |
CVE-2018-19249HIGH The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object c | Jan 3, 2019 | 7.5 | 24 | NO | NO |
CVE-2022-29188MEDIUM Smokescreen is an HTTP proxy. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of app | May 21, 2022 | 6.5 | 23 | NO | NO |
CVE-2024-45401HIGH stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin packa | Sep 5, 2024 | 7.1 | 21 | NO | NO |
CVE-2022-24825MEDIUM Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external atta | Apr 19, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stripe.
Media articles that mention a CVE ID that affects a product developed by Stripe — matched by CVE ID, not by vendor name.