WHMCS 9.1.0 Security Update
WHMCS 9.1.0 includes an undisclosed security fix (tracked internally as WHMCS-22707). WHMCS withholds technical details to protect customers who have not yet updated, so there is no CVE or CVSS data — the safe move is simply to update: run the unattended auto-update or update from the WHMCS Admin Area to 9.1.0 or later.
प्रभावित संस्करण
9.1.0
SharedLicense लाइसेंस के तहत इसका अर्थ
Because WHMCS has not disclosed the vulnerability, the affected surface is unknown — unpatched WHMCS installations should be treated as exposed until updated.
9.1 Change Log
WHMCS is working to improve the quality and availability of our supported languages. As a result, this and future WHMCS releases will include more updates and additions to localization files in the /lang and /admin/lang directories.
- These changes will not appear in the list of changelog entries.
- If you customize these files, we recommend reviewing the language string changes in each new WHMCS release before you update.
Version 9.1.0 (Beta) #
Implemented #
- WHMCS-20034 — Support for PHP 8.4
- WHMCS-20418 — Display notice of unsaved Ticket Scheduled Actions
- WHMCS-22150 — Unattended Auto Updates for Maintenance Releases
- WHMCS-24543 — Credit Notes Overview pages for Admin and Client Areas
- WHMCS-24545 — View & Print function added to Credit Notes in the Client Area
- WHMCS-24550 — Credit Notes support added to various reports and widgets
- WHMCS-24689 — Setup Tasks Admin Dashboard widget
- WHMCS-25096 — Stripe Dynamic Payments Gateway Module
- WHMCS-26207 — Configurable Email Import Limits
- WHMCS-27608 — Invoice Immutability and Credit Note Controls
Maintenance #
- WHMCS-18876 — Correct Promo Search on the Domains Tab
- WHMCS-19711 — Improved timestamp handling for Last Capture Attempt entries on Invoices
- WHMCS-22693 — Allow HTML5 video embedding in Knowledgebase Article body
- WHMCS-22707 — Undisclosed Security Fix
- WHMCS-24544 — Add Balance Column to Admin and Client Invoice Lists
- WHMCS-24769 — Correct TypeError on Automation Settings Page with empty values
- WHMCS-25011 — Improved error handling when allowing a grace period for an order.
- WHMCS-25049 — Improved calculations in Sales Tax Liability report
- WHMCS-25092 — Improved performance of Nexus Cart
- WHMCS-25172 — Improved handling of the “Mark Paid” button when updating an unpaid invoice
- WHMCS-25204 — Prevent Division By Zero Error When Downgrading a Recurring Product
- WHMCS-25214 — Correct Font Awesome Path Regex to Stop Repeated CSS Injection
- WHMCS-25294 — Improved handling of Fraud related Invoice statuses
- WHMCS-25622 — Improvements to the Mobile View of Nexus Theme
- WHMCS-25662 — Improved handling of PayPal payments in Stripe Dynamic Payments Gateway Module
- WHMCS-25709 — Improved handling of Automatic Domain Renewal setting
- WHMCS-25718 — Correct Upgrading a Marketplace Service via Nexus Cart
- WHMCS-25887 — Removal of Paid invoices from the Income by Product report.
- WHMCS-26041 — Undisclosed Security Fix
- WHMCS-26447 — Improved sorting of Affiliate tables in the Admin Area
- WHMCS-26561 — Correct IMAP Mail Import Using Stale Message IDs After Deletion
- WHMCS-27003 — Improve Performance of the Staff Online Admin Query
- WHMCS-27323 — Add System Health Check notice if storage locations are publicly writable
- WHMCS-27326 — Correct Apply-Once Promo Codes Being Rejected by Other Orders
- WHMCS-27427 — Enforce Block Existing Domains Setting for Direct Cart Links
- WHMCS-28009 — Permit multiple devices to hold an active Remember Me admin token
Modules #
- WHMCS-20973 — Switch module endpoint to use port 443 in PSIGate
- WHMCS-21414 — Correct scheme name for EUR transactions in GoCardless
- WHMCS-22763 — Update BitPay module to Unified SDK
- WHMCS-24148 — Improved process handling for PreInvoiceAutomaticCancellation hook point
- WHMCS-25097 — Implemented a migration feature for Stripe to Stripe Dynamic Gateway Modules
- WHMCS-26138 — Strengthen Generated Automatic Payment Password for WorldPay
- WHMCS-26190 — Improved handling of payment captures when using the Stripe Dynamic Payment Gateway
- WHMCS-26359 — Improve security around Staff Noticeboard
- WHMCS-26385 — Correct WP Toolkit provisioning in cPanel
- WHMCS-27404 — Update to XML RPC protocol version to 1.6.9.1 in Plesk
- WHMCS-27409 — Improve validation of API Endpoint URLs
- WHMCS-27443 — Correct SoapFault error during EV SSL Configuration for GlobalSign
- WHMCS-27532 — Update Suspension and Unsuspension in Plesk
- WHMCS-27812 — Update Change Password in Plesk
- WHMCS-27880 — Improve accuracy of Module Debug Logs in Plesk
API #
- WHMCS-24522 — Added Bundle Name to the Cart Item response payload in REST API
- WHMCS-24523 — Added Product Type to Bundle Items in the Cart response payload in REST API
- WHMCS-27181 — Undisclosed Security Fix
- WHMCS-27208 — Improve handling of Addon Billing Cycle in REST API
- WHMCS-27266 — Added headless checkout and payment endpoints to the REST API
Was this helpful?
Last modified: 2026 September 30
अक्सर पूछे जाने वाले प्रश्न
What is the WHMCS 9.1.0 security fix?
Which WHMCS versions are affected?
How do I update WHMCS to 9.1.0?
Is the WHMCS 9.1.0 vulnerability being exploited?
संदर्भ
अपने सिस्टम में भेद्यताओं की जाँच करें
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
अपना सिस्टम जाँचें