The security of our modules and our clients is paramount. That's why we encourage security researchers to analyze our modules and report any identified vulnerabilities to us, in line with responsible disclosure best practices.
We are committed to identifying and fixing any vulnerability, and to communicating transparently with all relevant parties throughout the process.
If you believe you have discovered a vulnerability in one of our modules, you may report it responsibly via: [your email]
Optional (at your discretion – remove if not applicable) Only reports submitted with our public GPG key [link to your GPG key] will be processed; all others are deleted upon receipt.
Please provide as much detail as possible (description, impact, affected version, reproduction steps).
Optional (at your discretion – remove if not applicable) We inform you that non-reproducible reports or those unrelated to our modules will be ignored.
In accordance with the TouchWeb Charter for Responsible Cybersecurity, our team applies the following principles:
In parallel, we make the following commitments to ensure responsible and ethical vulnerability handling:
We are fully aware that this transparency is essential to enable the relevant third parties (agencies, merchants, etc.) to meet their compliance obligations, particularly within the framework of the PCI-DSS standard or one of its simplified versions, such as SAQ-A.
We expressly authorize the company TouchWeb SAS to publish information related to patched vulnerabilities in our modules on its official website, in accordance with the commitments of the Responsible Cybersecurity Charter.
This publication may include:
Below is the list of known and patched security vulnerabilities:
| Date | Module | Version | CWE | CVSS | CVE | |
|---|---|---|---|---|---|---|
| Affected | Fixed | |||||
| 2024-10-15 | XYZ Payment Module | 2.3.0 to 2.3.4 | 2.3.5 | CWE-22 | 7.5 | CVE-AAAA-BBBB [Link to the CVE published on TouchWeb.fr] |