All 3 CVE vulnerabilities found in PayTR Virtual Pos iFrame API (v9x) WHMCS Module, with AI-generated Chinese analysis, references, and POCs.
Vendor: PayTR Payment and Electronic Money Institution Inc.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-16272 | Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module CWE-348 | 9.1 | Critical | 2026-09-09 |
| CVE-2026-16037 | Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module CWE-208 | 7.5 | High | 2026-09-08 |
| CVE-2026-16025 | Improper Payment Validation in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module CWE-1284 | 7.5 | High | 2026-09-08 |
All 3 known CVE vulnerabilities affecting PayTR Virtual Pos iFrame API (v9x) WHMCS Module with full Chinese analysis, references, and POCs where available.