VulnSea

ph7software has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was October 2026 with 3. The median CVSS is 6.5 (medium).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
3 prev 0

Products

  • ph7builder 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ph7software vulnerabilities

CVEs affecting ph7software, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-107636Medium· 6.5
today

pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields

pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can…

▾ Sunlitph7software · ph7buildervia NVD
CVE-2026-107638Medium· 6.8
today

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper restriction of authentication attempts vulnerability that allows attackers to bypass two-factor authentication by guessing TOTP codes without limits. Attackers who kno…

▾ Sunlitph7software · ph7buildervia NVD
CVE-2026-107637Medium· 4.3
today

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can s…

▾ Sunlitph7software · ph7buildervia NVD
ph7software vulnerabilities (CVEs) · VulnSea