EUVD Vulnerability Catalog

EUVD-2026-74769

Severity: CRITICAL Base Score: 9.1 CVSS Version: 3.1

Vulnerability Description

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality Impact (C): High
Integrity Impact (I): High
Availability Impact (A): None

Affected Vendors & Systems

Vendor PayTR Payment and Electronic Money Institution Inc.

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

TR-CERT

EPSS Probability

0

Known Aliases
GHSA-g622-qgc4-8v95 CVE-2026-16272
Published On

2026-09-09

Last Updated

2026-09-09