Whmcs
5 CVEs tracked since 2011. Since Dec 2011, none of them reached CISA KEV.
Whmcs CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2011-12 | 2 | 0 |
| 2012-01 | 2 | 0 |
| 2012-02 | null or fewer | |
| 2012-03 | null or fewer | |
| 2012-04 | null or fewer | |
| 2012-05 | null or fewer | |
| 2012-06 | null or fewer | |
| 2012-07 | null or fewer | |
| 2012-08 | null or fewer | |
| 2012-09 | null or fewer | |
| 2012-10 | null or fewer | |
| 2012-11 | null or fewer | |
| 2012-12 | null or fewer | |
| 2013-01 | null or fewer | |
| 2013-02 | null or fewer | |
| 2013-03 | null or fewer | |
| 2013-04 | null or fewer | |
| 2013-05 | 1 | 0 |
Products
The products that kept showing up in Whmcs's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Whmcs.
- CVE-2013-3536SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via...7.5
- CVE-2012-0693submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a different vulnerability than CVE-2011-5061. NOT...5.0
- CVE-2011-5061functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related ...7.5
- CVE-2011-4813Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invalid action and a ../ (dot dot slash) in the templ...5.0
- CVE-2011-4810Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitticket.php and (2)...5.0
- CVE-2010-1702SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.7.5
The record
- Peak rank
- #56 in Jan 2012
- Busiest month shown
- Dec 2011, 2 CVEs
- Months with a KEV entry
- 0 since Dec 2011
- Monthly snapshots
- 3 since 2011