CVE-2026-47198
Paymenter
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning parameters. Because bundled server extensions prioritize these user-supplied properties over administrator-defined configurations, a regular user can override hosting plans and resource limits at checkout without special privileges. The Checkout Livewire component's $checkoutConfig property exposed via URL query parameter...
- CVSS
- 8.5
- EPSS
- 0.29% 21.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.21