WHMCS is a widely deployed billing, provisioning, and client-management platform for hosting and service providers, with a concentrated product portfolio centered on its core suite and payment-processing components. Its vulnerability profile is characterized by recurring input-handling and access-control weaknesses—code injection, path traversal, and SQL injection—that are typical of web-facing administrative and billing systems; public exploit code has been available for many of its disclosures. Current counts and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whmcs over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1702HIGH SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter. | May 4, 2010 | 7.5 | 30 | NO | YES |
CVE-2013-3536HIGH SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary | May 13, 2013 | 7.5 | 28 | NO | YES |
CVE-2011-4810MEDIUM Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitt | Dec 14, 2011 | 5.0 | 27 | NO | YES |
CVE-2011-4813MEDIUM Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invalid action and a ../ (dot dot sl | Dec 14, 2011 | 5.0 | 26 | NO | YES |
CVE-2011-5061HIGH functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted | Jan 14, 2012 | 7.5 | 22 | NO | NO |
CVE-2012-0693MEDIUM submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a different vulnerability than C | Jan 14, 2012 | 5.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whmcs.
Media articles that mention a CVE ID that affects a product developed by Whmcs — matched by CVE ID, not by vendor name.