SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16037

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The PayTR Virtual Pos iFrame API (v9x) WHMCS Module versions prior to 9.0.3 are vulnerable to a timing discrepancy that can be exploited through black box reverse engineering techniques. This vulnerability could allow attackers to infer sensitive information or manipulate transactions, posing a significant risk to payment processing integrity. Organizations utilizing this module should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-16037
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.