Improper Input Validation in PayTR Payment iFrame API
CVE-2026-16025

7.5HIGH

What is CVE-2026-16025?

An improper validation issue exists in the PayTR Virtual Pos iFrame API WHMCS Module, specifically in versions from v9.0.0 before v9.0.3. This vulnerability allows attackers to manipulate input data by exploiting the way quantity is validated, potentially leading to unexpected behavior or data integrity issues.

Affected Version(s)

PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Efe KIRBAĹž
.