Vulnerabilities > Btcpayserver > Btcpay Server

DATE CVE VULNERABILITY TITLE RISK
2021-05-05 CVE-2021-29250 Cross-site Scripting vulnerability in Btcpayserver Btcpay Server
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality.
3.5
2021-04-01 CVE-2021-29251 Unspecified vulnerability in Btcpayserver Btcpay Server
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies).
network
btcpayserver
3.5
2021-03-26 CVE-2021-29249 Unspecified vulnerability in Btcpayserver Btcpay Server
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
network
low complexity
btcpayserver
5.0