CAPTCHA Bypass in pH7 Social Dating CMS by pH7Software
CVE-2026-108903

6.9MEDIUM

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108903?

The pH7Builder application, part of pH7 Social Dating CMS, is susceptible to a CAPTCHA bypass vulnerability in versions prior to 19.3.0. This flaw allows unauthenticated attackers to circumvent form validation by manipulating the form ID supplied to the PFBC Form::isValid() function. Attackers can exploit this vulnerability to access forms that normally require CAPTCHA verification, such as login or search forms, by submitting their chosen form ID along with their abusive data for contact, comment, forum, invite, or signup purposes. Consequently, this can lead to unauthorized actions and potential abuse of the system.

Affected Version(s)

ph7builder 0 < 19.3.0

ph7builder 19.3.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haluk Baran AKBULUT (CyberMap Group)
.