CVE-2019-20455: Globalpayments PHP SDK

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.

Affected products

Published 2020-02-14. Last modified 2026-06-17.