CVE-2026-107637

Source
https://cve.org/CVERecord?id=CVE-2026-107637
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107637.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107637
Published
2026-10-08T14:10:34Z
Modified
2026-10-10T02:47:23Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action
Details

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107637.json"
}
References

Affected packages

Git / github.com/ph7software/ph7-social-dating-cms

Affected ranges

Type
GIT
Repo
https://github.com/ph7software/ph7-social-dating-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "18.5.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.2.7
1.2.8
1.2.9
1.3.0
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
10.*
10.0.8
10.2.0
12.*
12.0.0
12.1.0
12.1.2
12.3.0
12.3.5
12.5.9
12.6.0
12.6.1
12.6.5
12.9.0
12.9.8
12.9.9
14.*
14.0.0
14.0.0-rc
14.0.0-rc2
14.0.0-rc3
14.3.0
14.3.4-rc
14.3.6
14.7.0
14.8.0
14.8.8
14.8.8-rc
14.8.8-rc2
14.8.9
14.9.0
14.9.0-rc
14.9.0-rc2
15.*
15.0.0
15.0.0-beta1
15.0.0-beta2
15.0.0-rc
15.1.0
15.1.0-beta
15.1.0-rc
15.1.0-rc2
15.1.6
15.1.7
15.1.8
15.2.0
15.3.0
15.3.0-rc.1
15.3.0-rc.3
15.4.0
15.4.0-beta.1
15.4.0-beta.2
16.*
16.0.0
16.0.0-beta.1
16.0.0-beta.2
16.0.0-rc.1
16.0.0-rc.2
16.0.0-rc.3
16.0.2-beta.1
16.1.0
16.1.0-beta.1
16.2.0
16.2.0-beta.1
16.2.2
16.3.0
16.3.0-beta.1
16.3.2
16.5.0.beta.1
17.*
17.0.0
17.0.0-beta.2
17.0.0-beta.3
17.0.1
17.1.0
17.1.2
17.1.8
17.1.8.beta.1
17.1.8.beta.2
17.2.0
17.2.0-beta.1
17.2.0-rc.1
17.2.0-rc.2
17.9.2-beta.1
17.9.2-beta.2
18.*
18.0.0-beta.1
18.0.0-beta.2
2.*
2.0.4
2.0.9
3.*
3.0.0
3.1.0
4.*
4.0.0
5.*
5.0.0
6.*
6.0.0
6.0.1
6.0.13
6.0.9
7.*
7.0.0
7.0.01
7.1.3
8.*
8.0.2
8.0.3
8.0.4
8.0.6
Other
untagged-de05a9b7f66bb64ad418
v17.*
v17.0.0
v17.0.0-beta.2
v17.9.0
v17.9.1
v17.9.1-beta.1
v17.9.2
v18.*
v18.1.0
v18.2.0
v18.3.0
v18.4.0
v18.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107637.json"