Problem
You see the following entry in the Activity Log at Configuration () > System Logs:
Password history depth "<value>" is outside the permitted range 4 to 40. Using 4.
Cause
The stored value for the Password Reuse Limit setting in the Security tab at Configuration () > System Settings > General Settings is outside its permitted range.
This can occur if something outside of the Admin Area changes the value. For example, something edited the WHMCS database directly, or a migration or restored backup changed the value.
If this occurs, WHMCS ignores the out-of-range stored value and uses 4 (the PCI DSS-mandated minimum) instead. The entry will recur in the log until you correct the value.
Solution
To resolve this issue:
- Go to the Security tab at Configuration () > System Settings > General Settings.
- Set Password Reuse Limit to a whole number that is between
4and40. - Click Save Changes.
Last modified: 2026 September 30