Databases are commonly compromised by SQL injection attacks that reveal the contents of the database. Some databases, MySQL for example, have functions that allow the database to display the contents of files off the filesystem. But on the whole, if someone has gained access to your database it does not immediately follow that they have access to your code. Only that you need to tighten up on security.
An alternative to hashes, but somewhat more expensive computationally, would be to encrypt the CC number into the database using the public key of a Public/Private encryption scheme (PGP for example). So even if they got hold of your database and the public key they could still not, realistically, decode the CC number. Providing the private key is held securely on another server!
It all comes down to what you need to do with the CC numbers. Long ago I worked on some software to track CC fraud for a major store (was a CC number used in store A also being used in store B, it was likely that the card had been cloned as most customers only shopped at their local branch), we used hashes of the numbers. We didn't even need to know who the customer was, everything was driven by electronic till receipts and hashed CC number.
Do you need the actual CC numbers or would a hash be equally as usable?