Skip to finding
important · RCE — Hosting automation

An unauthenticated WHMCS visitor can execute code in the hosting-automation server context.

Affects

WHMCS, a self-hosted billing and web-hosting automation application commonly deployed on Internet-facing servers.

WHMCS says a forged payload can reach executable server-side processing without an account or user interaction and compromise the installation.

Detail and 2 sources

A fix has shipped, but the path has no public technical reproduction or exploit code.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026