WebPros / Whmcs
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-67399 | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code. | CRITICAL | 9.3 | Sep 14, 2026 |
| CVE-2026-67398 | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL… | HIGH | 8.2 | Sep 3, 2026 |
| CVE-2026-29204 | Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownersh… | CRITICAL | 9.1 | May 12, 2026 |
Showing 1 to 3 of 3 CVEs