PatchSiren

Nexi Payments CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Nexi Payments CVE published 2026-06-17

CVE-2026-54810

CVE-2026-54810 is a high-severity vulnerability in Nexi Payments' Nexi XPay plugin, affecting versions from n/a to 8.3.1. The issue is a Missing Authorization vulnerability, which allows attackers to exploit incorrectly configured access control security levels. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE was published on 2026-06-17T15:17:01.240Z and last modified o [truncated]