Compassplus

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-66574

    TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS)

    Last Modified: Apr 07, 2026
    Published: Dec 04, 2025

    CVE-2021-43106

    A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. This is due to that the server implicitly trusts the Host header, and fails to validate or escape it properly. An attacker can use this input to redirect target users to a malicious domain/web page. This would result in expanding the potential to further attacks and malicious actions.

    Last Modified: Nov 21, 2024
    Published: Feb 14, 2022

    CVE-2021-28126

    index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2021

    CVE-2021-28110

    /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2021

    CVE-2021-28109

    TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2021
    Items Per Page
    Compassplus Vulnerabilities & Security CVEs | CVE-DB