SecAlerts
paypal logo

paypal

Security Risk Profile

41
/100
medium

Security Risk Score

Comprehensive risk assessment based on 39 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 13, 2006 to present

39
Total CVEs
4
Critical+High
1
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
5.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
41/100
medium
⚠️ 1 Active Exploits📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
3
Medium
29
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Input Validation
12
2
XSS
10
3
CSRF
2
4
SQL Injection
1
5
Command Injection
1

Most Affected Products

1. Apache Axis25
2. Paypal PayPal6
3. IBM Data Virtualization on Cloud Pak for Data6
4. IBM Watson Query on Cloud Pak for Data6
5. osCommerce Online Merchant4

Recent Vulnerabilities

See more →
CVE-2026-15502
CVSS 5.3medium

AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection

7/12/2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1u9d9kn/authenticating_a_paypal_notification_is_not_the/
unknown

Authenticating a PayPal notification is not the same as trusting what it says (CVE-2026-9189)

6/18/2026🔧 No Patch
CVE-2025-12752
CVSS 5.3medium

Subscriptions & Memberships for PayPal <= 1.1.7 - Unauthenticated Fake Payment Creation

11/22/2025🔧 No Patch
CVE-2025-11859
CVSS 6.4medium

Paypal Donation Shortcode <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

11/11/2025🔧 No Patch
CVE-2025-10309
CVSS 4.3medium

PayPal Forms <= 1.0.3 - Cross-Site Request Forgery

10/3/2025🔧 No Patch
https://www.theregister.com/2025/08/28/euro_banks_block_paypal_direct_debits/
unknown

Euro banks block billions in rogue PayPal direct debits after fraud glitch

8/28/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/phishers-abuse-google-oauth-to-spoof-google-in-dkim-replay-attack/
unknown

Phishers abuse Google OAuth to spoof Google in DKIM replay attack

4/20/2025🔧 No Patch
CVE-2024-13560
CVSS 4.3medium

Subscriptions & Memberships for PayPal <= 1.1.6 - Cross-Site Request Forgery to Arbitrary Post Deletion

2/26/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/
unknown

Beware: PayPal "New Address" feature abused to send phishing emails

2/22/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/paypal-to-pay-2-million-settlement-over-2022-data-breach/
unknown

PayPal to pay $2 million settlement over 2022 data breach

1/25/2025⚠ Exploited🔧 No Patch

Monitor paypal in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

paypal Security Vulnerabilities & Risk Score | 39 CVEs | SecAlerts - SecAlerts