SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16025

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The PayTR Virtual Pos iFrame API (v9x) WHMCS Module versions prior to 9.0.3 are vulnerable due to improper validation of input data, allowing for potential input data manipulation. This could lead to unauthorized transactions or financial fraud, posing a significant risk to businesses utilizing this payment processing solution. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-16025
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.