Information Disclosure in pH7Builder by pH7 Software
CVE-2026-108904

7.1HIGH

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108904?

pH7Builder, a social dating CMS developed by pH7 Software, is impacted by an information disclosure flaw. This vulnerability allows API clients to access sensitive member information, including bcrypt password hashes, reset tokens, and TOTP secrets. Attackers with a valid private API key can exploit the unfiltered data returned by the UserController::users() and user() methods, potentially leading to account takeovers and the circumvention of two-factor authentication. It is crucial for users to update to version 18.5.0 or later to mitigate this risk.

Affected Version(s)

ph7builder 0 < 18.5.0

ph7builder 18.5.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haluk Baran AKBULUT (CyberMap Group)
.