Travelpayouts is a travel-affiliate and booking-integration platform with a narrow, focused product footprint centered on its core travelpayouts offering. Its vulnerability signal is anchored in application-layer web issues including cross-site request forgery, cross-site scripting, and open-redirect vulnerabilities, reflecting the input-handling and trust-boundary challenges inherent to affiliate and payment-redirect systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Travelpayouts over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0337MEDIUM The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variab | Mar 20, 2024 | 6.1 | 28 | NO | YES |
CVE-2025-68042MEDIUM Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpa | Feb 20, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-5934HIGH The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers | May 15, 2025 | 7.3 | 22 | NO | NO |
CVE-2023-5932MEDIUM The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec | May 15, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Travelpayouts.
Media articles that mention a CVE ID that affects a product developed by Travelpayouts — matched by CVE ID, not by vendor name.