Products: 2
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-11575

    PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback

    Last Modified: Aug 02, 2026
    Published: Jul 17, 2026

    CVE-2025-5154

    PhonePe App SQLite Database databases cleartext storage in a file or on disk

    Last Modified: Jun 03, 2025
    Published: May 25, 2025

    CVE-2022-45835

    WordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF)

    Last Modified: Apr 28, 2026
    Published: Nov 13, 2023

    CVE-2018-17402

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number, expiration date, and CVV number. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots

    Last Modified: Nov 21, 2024
    Published: Sep 23, 2018

    CVE-2018-17400

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by intercepting the user name and PIN during the initial configuration of the application. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots

    Last Modified: Nov 21, 2024
    Published: Sep 23, 2018
    Items Per Page
    Phonepe Vulnerabilities & Security CVEs | CVE-DB