Back to Security Advisories
More Information
Medium
2026-08-06
Security Advisory: WHMCS Stored XSS
WHMCS
A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.
Affected Versions
8.7.0 and earlier
Patched Version
8.7.1
Default Update CMD
yum update -y
Fix Commands
Any supported OS
cd /var/www/html php composer.phar update whmcs/core
A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System