A real, pre-generated result — not a live call. This is exactly what you get.
stripe.com attack-surface scan · 4/4 data sources responded
stripe.com presents a low-to-moderate threat surface driven by third-party ecosystem CVEs and OTX phishing signals, not direct infrastructure compromise.
- HIGH: CVE-2026-54308 (CVSS 7.2) — n8n StripeTrigger accepts forged webhooks; unauthenticated RCE-equivalent workflow execution risk for integrators
- MEDIUM: CVE-2026-12093 (CVSS 5.3) — WordPress Simple Membership allows account deactivation via forged Stripe webhook if no signing secret is configured
- MEDIUM: CVE-2026-57521 (CVSS 4.3) — Bitwarden IDOR exposes any org billing/subscription data via Stripe preview invoice endpoints
- MEDIUM: OTX phishing flag — stripe.com cited in 42 threat reports across 10 malware/phishing pulses; high brand-impersonation abuse signal
- LOW: CVE-2026-56330 (CVSS 3.5) — Capgo open redirect via unvalidated Stripe billing URLs enables credential-harvesting phishing
cve_analysisemail_auth_healthnpm_package_riskregistrar_domain_hygienetech_stack_exposurethreat_indicators
MINT attestation (verified on Solana)
de981d69ded319e15daf43a45c88251e457cb980764d030ce8dbe4375ae4830f