Known vulnerabilities in Nexi XPay
XPay is the payment gateway provided by Nexi, a leading group in Italy with the goal of shaping the future of digital payments.
2Reported vulnerabilities
5.3Highest CVSS score
8.4.0Latest version
7,000+Active installs
What to do now
Update Nexi XPay to 8.3.2 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-54810 | Medium | 0.2% | 8.3.1 and earlier | 8.3.2 |
June 17, 2026 |
| CVE-2025-15565 | Medium | 0.2% | 0 to 8.3.0 (inclusive) | 8.3.2 |
April 14, 2026 |