High severity7.5NVD Advisory· Published Sep 8, 2026
CVE-2026-16037
CVE-2026-16037
Description
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Affected products
1- PayTR Payment And Electronic Money Institution Inc./PayTR Virtual Pos iFrame API (v9x) WHMCS Modulellm-createRange: v9.0.0 <= v < v9.0.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.