[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-16272":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-09T09:01:21.974Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":96,"aliases":97,"duplicate_of":9,"upstream":98,"downstream":99,"duplicates":100,"related":101,"reserved_at":9,"published_at":102,"modified_at":102,"state":103,"summary":104,"references_raw":111,"kevs":118,"epss":9,"epss_history":119,"metrics":120,"affected":128},"CVE-2026-16272","Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers.\n\nThis issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-348","Use of Less Trusted Source","The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.","weakness","Draft","Base",[19,72,84,88,92],{"id":20,"name":21,"techniques":22},"CAPEC-141","Cache Poisoning",[23],{"id":24,"name":25,"tactics":26,"countermeasures":33},"T1557.002","ARP Cache Poisoning",[27,30],{"id":28,"name":29},"TA0031","Credential Access",{"id":31,"name":32},"TA0100","Collection",[34,39,44,48,52,56,60,64,68],{"id":35,"name":36,"tactic":37},"D3-NTF","Network Traffic Filtering",{"name":38},"Isolate",{"id":40,"name":41,"tactic":42},"D3-NTCD","Network Traffic Community Deviation",{"name":43},"Detect",{"id":45,"name":46,"tactic":47},"D3-RTSD","Remote Terminal Session Detection",{"name":43},{"id":49,"name":50,"tactic":51},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":43},{"id":53,"name":54,"tactic":55},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":43},{"id":57,"name":58,"tactic":59},"D3-CSPP","Client-server Payload Profiling",{"name":43},{"id":61,"name":62,"tactic":63},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":43},{"id":65,"name":66,"tactic":67},"D3-NTSA","Network Traffic Signature Analysis",{"name":43},{"id":69,"name":70,"tactic":71},"D3-APCA","Application Protocol Command Analysis",{"name":43},{"id":73,"name":74,"techniques":75},"CAPEC-142","DNS Cache Poisoning",[76],{"id":77,"name":78,"tactics":79,"countermeasures":83},"T1584.002","DNS Server",[80],{"id":81,"name":82},"TA0042","Resource Development",[],{"id":85,"name":86,"techniques":87},"CAPEC-73","User-Controlled Filename",[],{"id":89,"name":90,"techniques":91},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":93,"name":94,"techniques":95},"CAPEC-85","AJAX Footprinting",[],[],[],[],[],[],[],"2026-09-09T08:17:50.299Z","Received",{"cisa_kev":105,"cisa_ransomware":105,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":106,"severity_score":107,"severity_version":108,"severity_source":109,"severity_vector":110,"severity_status":103},false,"critical",9.1,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",[112],{"url":113,"sources":114,"tags":116},"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1034",[109,115],"nvd",[117],"Government Resource",[],[],[121,126],{"source":109,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":122,"cvss_v4_0":9},{"baseScore":107,"baseSeverity":123,"vectorString":110,"impactScore":124,"exploitabilityScore":125},"CRITICAL",8.7,10,{"source":115,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":127,"cvss_v4_0":9},{"baseScore":107,"baseSeverity":123,"vectorString":110,"impactScore":124,"exploitabilityScore":125},[129],{"ecosystem":9,"name":130,"vendor":131,"product":132,"cpe_part":133,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":134},"PayTR Virtual Pos iFrame API (v9x) WHMCS Module","paytr payment and electronic money institution inc.","paytr virtual pos iframe api (v9x) whmcs module","a",[135],{"version":136,"is_range":137,"range_type":109,"version_start":138,"version_start_type":139,"version_end":140,"version_end_type":141,"fixed_in":9},">= v9.0.0, \u003C v9.0.3",true,"v9.0.0","including","v9.0.3","excluding"]