Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks. | |
| Title | pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T14:47:57.461Z
Reserved: 2026-10-08T14:06:00.033Z
Link: CVE-2026-107637
Updated: 2026-10-08T14:47:53.297Z
Status : Deferred
Published: 2026-10-08T15:17:46.737
Modified: 2026-10-08T15:17:46.873
Link: CVE-2026-107637
No data.
OpenCVE Enrichment
No data.