EUVD Vulnerability Catalog
EUVD-2026-74769
Severity: CRITICAL
Base Score: 9.1
CVSS Version: 3.1
Vulnerability Description
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): None
Affected Vendors & Systems
Vendor
PayTR Payment and Electronic Money Institution Inc.
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
TR-CERT
EPSS Probability
0
Known Aliases
GHSA-g622-qgc4-8v95
CVE-2026-16272
Published On
2026-09-09
Last Updated
2026-09-09