Exposure of WHMCS
CMS20
exposure score
1,549
sites use
0
exploited
2
critical
CVEs
3 resultsCVE-2026-67399CRITICALDeserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.EPSS 0.7%CVE-2026-29204CRITICALInsufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` EPSS 0.3%CVE-2026-67398HIGHMissing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9EPSS 0.3%