CAPTCHA Bypass in pH7 Social Dating CMS by pH7Software
CVE-2026-108903
6.9MEDIUM
What is CVE-2026-108903?
The pH7Builder application, part of pH7 Social Dating CMS, is susceptible to a CAPTCHA bypass vulnerability in versions prior to 19.3.0. This flaw allows unauthenticated attackers to circumvent form validation by manipulating the form ID supplied to the PFBC Form::isValid() function. Attackers can exploit this vulnerability to access forms that normally require CAPTCHA verification, such as login or search forms, by submitting their chosen form ID along with their abusive data for contact, comment, forum, invite, or signup purposes. Consequently, this can lead to unauthorized actions and potential abuse of the system.
Affected Version(s)
ph7builder 0 < 19.3.0
ph7builder 19.3.0
