CVE Tools

Whmcs

5 CVEs tracked since 2011. Since Dec 2011, none of them reached CISA KEV.

Whmcs CVEs per month

Dec 2011 to May 2013. Point at a month, or focus the strip and use the arrow keys.
Whmcs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-1220
2012-0120
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-0510

Products

The products that kept showing up in Whmcs's monthly top three, with their CVEs summed over those months.

  1. Whmcompletesolution42 months
  2. Group Pay11 month

Latest CVEs

The 6 most recently published vulnerabilities affecting Whmcs.

  1. CVE-2013-3536SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via...7.5
  2. CVE-2012-0693submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a different vulnerability than CVE-2011-5061. NOT...5.0
  3. CVE-2011-5061functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related ...7.5
  4. CVE-2011-4813Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invalid action and a ../ (dot dot slash) in the templ...5.0
  5. CVE-2011-4810Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitticket.php and (2)...5.0
  6. CVE-2010-1702SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.7.5

The record

Peak rank
#56 in Jan 2012
Busiest month shown
Dec 2011, 2 CVEs
Months with a KEV entry
0 since Dec 2011
Monthly snapshots
3 since 2011
Whmcs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store