PT-2026-87109 · Paytr Payment Electronic Money Institution · Paytr Virtual Pos Iframe Api (V9X) Whmcs Module

·

CVE-2026-16037

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16037

Affected Products

Paytr Virtual Pos Iframe Api (V9X) Whmcs Module