Description
pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse.
Published: 2026-10-11
Score: 6.9 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse.
Title pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:58:05.502Z

Reserved: 2026-10-11T14:47:10.598Z

Link: CVE-2026-108903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T15:16:56.490

Modified: 2026-10-11T15:16:56.600

Link: CVE-2026-108903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses