← Back

Btcpay Server

btcpay_server

Vendor: Btcpayserver • 13 CVEs

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Mar 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Feb 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Jan 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the st...Show more
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.Show less
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Jan 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Sep 26, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Sep 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Btcpayserver
1Btcpay Server
Jun 17, 2026
May 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
May 5, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
May 5, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
May 5, 2021
N/A· v4
6.7 MEDIUM· v3
6.5 MEDIUM· v2
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload...Show more
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.Show less
1Btcpayserver
1Btcpay Server
Jun 17, 2026
May 5, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
1Btcpayserver
1Btcpay Server
Jun 17, 2026
Mar 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.