CVE-2021-28126: Compassplus Tranzware E-Commerce Payment Gateway

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability

Affected products

  • Compassplus Tranzware E-Commerce Payment Gateway: before 3.1.27.5 (fixed in 3.1.27.5)

Published 2021-03-19. Last modified 2026-06-17.