Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-13461: PayRange 7.0.7 allows malicious JavaScript on Android devices
CVE-2026-13461
CVE-2026-13461
Summary
A security weakness in PayRange 7.0.7 for Android allows attackers to inject malicious code on users' devices, potentially leading to unauthorized actions. This issue is particularly concerning when combined with another security flaw. To protect users, update to a fixed version of the PayRange app as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| payrange | payrange | 7.0.7 |
Original title
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker ...
Original description
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
Vulnerability type
CWE-94
Code Injection
Published: 9 Jul 2026 · Updated: 20 Jul 2026 · First seen: 9 Jul 2026