Back to Security Advisories
Medium 2026-08-06

Security Advisory: WHMCS Stored XSS

WHMCS

A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.

Affected Versions

8.7.0 and earlier

Patched Version

8.7.1

Default Update CMD

yum update -y

Fix Commands

Any supported OS

cd /var/www/html
php composer.phar update whmcs/core

A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System