Improper Input Validation in PayTR Payment iFrame API
CVE-2026-16025
7.5HIGH
Key Information:
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-16025?
An improper validation issue exists in the PayTR Virtual Pos iFrame API WHMCS Module, specifically in versions from v9.0.0 before v9.0.3. This vulnerability allows attackers to manipulate input data by exploiting the way quantity is validated, potentially leading to unexpected behavior or data integrity issues.
Affected Version(s)
PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0
