pay
RubyGems2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting paypage 1 of 1
- CVE-2023-30614HIGHCVSS 7.1EG 7.1✓ Fixed in 6.3.22023-04-19
vulnerable: 0.0.0 ... 6.3.1 (96 versions)
Pay is a payments engine for Ruby on Rails 6.0 and higher. In versions prior to 6.3.2 a payments info page of Pay is susceptible to reflected Cross-site scripting. An attacker could create a working URL that renders a javascript link to a …
- CVE-2026-70658HIGHCVSS 7.4EG 7.42026-09-14
vulnerable: 0.0.0 ... 9.0.1 (155 versions)
Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMA…
Check whether pay is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pay CVEs against the assets you own.
Start Free Scan →