<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – PCI-DSS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/pci-dss.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/pci-dss-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – PCI-DSS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-13371 – The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Expos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13371</guid>
    <pubDate>Wed, 07 Jan 2026 12:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13371</strong></p>
  <p>The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the plugin storing full payment card details (PAN, card holder name, expiry month/year, and CVV) in WordPress post_meta using base64_encode(), and then embedding these values into the publicly accessible mspaylink page's inline JavaScript without any aut…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38155 – OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38155</guid>
    <pubDate>Fri, 06 Aug 2021 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38155</strong></p>
  <p>OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38155">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
