---
id: CVE-2026-37604
title: >-
  pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the
  client IP address in _protected/framework/Ip/Ip.class.php from the
  HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request
  comes from a trus…
summary: >-
  pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the
  client IP address in _protected/framework/Ip/Ip.class.php from the
  HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request
  comes from a trus…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-444
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T16:16:42.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-37604'
references:
  - url: >-
      https://cybermapgroup.com/en/blog/admin-brute-force-protection-bypass-chain-in-ph7builder
    label: cve@mitre.org
  - url: 'https://github.com/pH7Software/pH7-Social-Dating-CMS'
    label: cve@mitre.org
  - url: 'https://ph7builder.com'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-23T15:16:19.430426Z'
epss: 0.00657
epssPercentile: 0.49225
ingestedAt: '2026-09-22T19:09:10.006Z'
---

## Overview

pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
