« Back to list

Ph7software

Ph7software Ph7builder: vulnerabilities and CVEs

Ph7software Ph7builder has 2 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-37604Critical (9.8)0.66%—Sep 22, 2026
pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request…
CVE-2026-37603Medium (6.5)0.50%—Sep 22, 2026
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1078.001 Default Accounts1
  3. T1110.003 Password Spraying1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.