Bounties
Partners
Community
Info
btcpayserver / btcpayserver
Project repository
Accept Bitcoin payments. Free, open-source & self-hosted, Bitcoin payment processor.
Submit a report
FIRST INTERACTION
WITHIN
1 DAY
REVIEW
WITHIN
3 DAYS
FIX
WITHIN
6 DAYS
Defect report dundle double spend vulnerability
Oct 16th 2023
katzamit99
•
not applicable
HTML Injection in App Pos and App Crowdfund
Mar 14th 2023
jobert-krohnen
•
informative
Medium
SSRF
Mar 12th 2023
hatlesswizard
•
informative
Medium
btcpayserver Store plugins Shopify
Mar 11th 2023
ahmadsahimdova
•
informative
Medium
XSS via Client Side Template Injection
Mar 8th 2023
cupc4k3
•
Medium
Medium
•
CVE-2023-1270
CVE-2023-1270
Broken Authentication and Session Management
Feb 23rd 2023
thewhiteevil
•
informative
Medium
Stored HTML Injection inside the >>> Request payment >>> Request Customer Data C...
Mar 2nd 2023
thewhiteevil
•
Medium
Medium
•
CVE-2023-1149
CVE-2023-1149
SSRF vulnerability in User's Store Setting under webhooks functions
Feb 15th 2023
jeffreygaor
•
informative
High
Unrestricted File Upload Leads to Cross-Site Scripting Stored & Potential Remote...
Feb 15th 2023
jeffreygaor
•
duplicate
High
Valid session after logout
Feb 15th 2023
isdkrisna
•
not applicable
File Upload lead to Stored XSS bypass csp
Feb 17th 2023
nayefhmoodh
•
Medium
Medium
•
CVE-2023-0879
CVE-2023-0879
Stored XSS in server settings when upload branding
Feb 13th 2023
d47sec
•
High
High
•
CVE-2023-0810
CVE-2023-0810
Stored XSS in server settings when upload theme
Feb 11th 2023
d47sec
•
duplicate
High
Weak Filetype validation to potential various security issues
Feb 14th 2023
kr1shna4garwal
•
informative
Medium
Exif Meta Data not striped off (Geo location leak)
Feb 7th 2023
thewhiteevil
•
not applicable
Open Redirect on "returnUrl=" parameter
Feb 8th 2023
gonzxph
•
Medium
Medium
•
CVE-2023-0748
CVE-2023-0748
Weak password policy : Old password can be set as new password
Jan 26th 2023
ctflearner
•
informative
Low
File Upload Type Validation Error lead to Stored XSS
Feb 8th 2023
ctflearner
•
Medium
Medium
•
CVE-2023-0747
CVE-2023-0747
Stored HTML Injection
Jan 25th 2023
thewhiteevil
•
Medium
Medium
•
CVE-2023-0493
CVE-2023-0493
Pre-account takeover due to lack of email verification.
Jan 23rd 2023
thewhiteevil
•
informative
Low
Cross-site Scripting (XSS) - Reflected
Sep 9th 2021
b3ef
•
Medium
•
$40
Medium
•
$40
•
CVE-2021-3646
CVE-2021-3646
Cross-site Scripting (XSS) - Stored
Sep 10th 2021
ranjit-git
•
High
•
$40
High
•
$40
Cross-site Scripting (XSS) - Stored
Sep 9th 2021
b1nslashsh
•
Low
•
$40
Low
•
$40
•
CVE-2021-3830
CVE-2021-3830
Cross-site Scripting (XSS) - Stored
Sep 9th 2021
b1nslashsh
•
Medium
•
$40
Medium
•
$40
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0