Skip to finding
important · Edge devices

Unauthenticated requests can execute code in the WHMCS server context.

Affects

WHMCS, a web-hosting billing and customer-management application deployed on PHP web servers.

A forged request to an affected public WHMCS application reaches an executable context without credentials and runs with the web-server process's privileges.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026