Search
Search Results (11 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108902 | 1 Ph7software | 1 Ph7builder | 2026-10-11 | 8.1 High |
| pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service. | ||||
| CVE-2026-108903 | 1 Ph7software | 1 Ph7builder | 2026-10-11 | 5.3 Medium |
| pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse. | ||||
| CVE-2026-108904 | 1 Ph7software | 1 Ph7builder | 2026-10-11 | 6.5 Medium |
| pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication. | ||||
| CVE-2026-108905 | 1 Ph7software | 1 Ph7builder | 2026-10-11 | 7.5 High |
| pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields. | ||||
| CVE-2026-107638 | 1 Ph7software | 1 Ph7builder | 2026-10-08 | 6.8 Medium |
| pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who know an account password can submit unlimited 6-digit verification codes to VerificationCodeFormProcess.php to take over member, affiliate, or administrator accounts. | ||||
| CVE-2026-107636 | 1 Ph7software | 1 Ph7builder | 2026-10-08 | 6.5 Medium |
| pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features. | ||||
| CVE-2026-107637 | 1 Ph7software | 1 Ph7builder | 2026-10-08 | 4.3 Medium |
| pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks. | ||||
| CVE-2026-37604 | 1 Ph7software | 1 Ph7builder | 2026-10-05 | 6.5 Medium |
| pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request | ||||
| CVE-2026-37603 | 1 Ph7software | 1 Ph7builder | 2026-09-23 | 6.5 Medium |
| Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge. | ||||
| CVE-2025-63645 | 2 Ph7builder, Ph7software | 2 Ph7 Social Dating Builder, Ph7-social-dating-cms | 2026-02-13 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted by the server and later rendered in another user's Inbox view without appropriate context-aware encoding. As a result, attacker-controlled content executes in the recipient's browser context when the Inbox message is viewed. | ||||
| CVE-2025-63644 | 2 Ph7builder, Ph7software | 2 Ph7 Social Dating Builder, Ph7-social-dating-cms | 2026-01-23 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile Description field. | ||||
Page 1 of 1.