PatchSiren

Paymenter CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Paymenter CVE published 2026-07-20

CVE-2026-47198

CVE-2026-47198 is a HIGH severity vulnerability in Paymenter, a free and open-source webshop solution. The checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning parameters. This issue has been fixed in version 1.5.1. The vulnerability allows a regular user to override hosting plans and resource limits at che [truncated]