CVE-2026-49064: Stiofan Getpaid

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

Affected products

  • Stiofan Getpaid: up to and including 2.8.49

Published 2026-06-15. Last modified 2026-06-17.