Filtered by vendor Technical-laohu Subscriptions
Filtered by product Mpay Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-1151 1 Technical-laohu 1 Mpay 2026-01-20 2.4 Low
A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-1152 1 Technical-laohu 1 Mpay 2026-01-20 4.7 Medium
A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code Image Handler. Such manipulation of the argument codeimg leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-1153 1 Technical-laohu 1 Mpay 2026-01-20 4.3 Medium
A vulnerability was detected in technical-laohu mpay up to 1.2.4. This affects an unknown function. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. The exploit is now public and may be used.