Whmcs
This hub aggregates every CVE we track for Whmcs, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
2
Critical
1
High
0
In CISA KEV
Severity distribution
CRITICAL2HIGH1MEDIUM1
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2024-072026-06
Latest CVEs
The 4 most recently published vulnerabilities affecting Whmcs.
- CVE-2026-29204Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorize...9.1
- CVE-2024-9193WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update9.8
- CVE-2022-0855Improper Resolution of Path Equivalence in microweber-dev/whmcs_plugin6.1
- CVE-2010-1702SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.7.5
Product normalization is registry-driven with AI assist and human review. How it works