Path Traversal Vulnerability in pH7 Social Dating CMS by pH7 Software
CVE-2026-108902

7.2HIGH

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108902?

The pH7 Social Dating CMS prior to version 18.5.0 is susceptible to a path traversal vulnerability in the picture module's deletePhoto() action. This vulnerability enables authenticated users to manipulate the POST parameter 'picture_link' to include '../' sequences, potentially allowing them to delete arbitrary files. As a result, this can lead to unauthorized deletion of other users' photos or critical configuration and cache files, causing loss of content and creating denial of service conditions. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

ph7builder 0 < 18.5.0

ph7builder 18.5.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haluk Baran AKBULUT (CyberMap Group)
.