CVE-2026-16025 and CVE-2026-16037: Vulnerabilities in PayTR Virtual Pos iFrame API

CVE-2026-16025 and CVE-2026-16037: Vulnerabilities in PayTR Virtual Pos iFrame API

First seen 9 Sep 2026, 00:42 UTC Redpacketsecurity 57.8

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in the PayTR Virtual Pos iFrame API (v9x) WHMCS Module, both published on 2026-09-08. CVE-2026-16025 involves improper validation of input quantities, allowing attackers to manipulate transaction data, potentially leading to revenue loss and customer disputes. CVE-2026-16037 features a timing discrepancy vulnerability that could enable black box reverse engineering, undermining payment callback authentication. Both vulnerabilities affect versions from v9.0.0 to before v9.0.3 and pose high risks to internet-facing WHMCS installations, particularly those handling high-value transactions. Currently, there is no evidence of active exploitation for either vulnerability, but they require urgent attention and remediation. Administrators are urged to apply vendor patches and monitor for suspicious activity.

Key Points: • CVE-2026-16025 allows input data manipulation in payment transactions. • CVE-2026-16037 enables black box reverse engineering of payment callbacks. • Both vulnerabilities affect PayTR Virtual Pos iFrame API versions 9.0.0 to 9.0.2.

Ask AI about this cluster

Timeline

2026-09-08
CVE-2026-16025 published
Improper input validation vulnerability in PayTR Virtual Pos iFrame API allows transaction manipulation.
Redpacketsecurity
2026-09-08
CVE-2026-16037 published
Timing discrepancy vulnerability in PayTR API could allow black box reverse engineering of callbacks.
Redpacketsecurity