CVE-2026-37603

Source
https://cve.org/CVERecord?id=CVE-2026-37603
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-37603.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-37603
Published
2026-09-22T00:00:00Z
Modified
2026-09-24T03:45:22Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37603.json"
}
References

Affected packages

Git / github.com/ph7software/ph7-social-dating-cms

Affected ranges

Type
GIT
Repo
https://github.com/ph7software/ph7-social-dating-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "19.2.0"
        }
    ],
    "source":  "DESCRIPTION"
}

Affected versions

1.*
1.2.7
1.2.8
1.2.9
1.3.0
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
10.*
10.0.8
10.2.0
12.*
12.0.0
12.1.0
12.1.2
12.3.0
12.3.5
12.5.9
12.6.0
12.6.1
12.6.5
12.9.0
12.9.8
12.9.9
14.*
14.0.0
14.0.0-rc
14.0.0-rc2
14.0.0-rc3
14.3.0
14.3.4-rc
14.3.6
14.7.0
14.8.0
14.8.8
14.8.8-rc
14.8.8-rc2
14.8.9
14.9.0
14.9.0-rc
14.9.0-rc2
15.*
15.0.0
15.0.0-beta1
15.0.0-beta2
15.0.0-rc
15.1.0
15.1.0-beta
15.1.0-rc
15.1.0-rc2
15.1.6
15.1.7
15.1.8
15.2.0
15.3.0
15.3.0-rc.1
15.3.0-rc.3
15.4.0
15.4.0-beta.1
15.4.0-beta.2
16.*
16.0.0
16.0.0-beta.1
16.0.0-beta.2
16.0.0-rc.1
16.0.0-rc.2
16.0.0-rc.3
16.0.2-beta.1
16.1.0
16.1.0-beta.1
16.2.0
16.2.0-beta.1
16.2.2
16.3.0
16.3.0-beta.1
16.3.2
16.5.0.beta.1
17.*
17.0.0
17.0.0-beta.2
17.0.0-beta.3
17.0.1
17.1.0
17.1.2
17.1.8
17.1.8.beta.1
17.1.8.beta.2
17.2.0
17.2.0-beta.1
17.2.0-rc.1
17.2.0-rc.2
17.9.2-beta.1
17.9.2-beta.2
18.*
18.0.0-beta.1
18.0.0-beta.2
2.*
2.0.4
2.0.9
3.*
3.0.0
3.1.0
4.*
4.0.0
5.*
5.0.0
6.*
6.0.0
6.0.1
6.0.13
6.0.9
7.*
7.0.0
7.0.01
7.1.3
8.*
8.0.2
8.0.3
8.0.4
8.0.6
Other
untagged-de05a9b7f66bb64ad418
v17.*
v17.0.0
v17.0.0-beta.2
v17.9.0
v17.9.1
v17.9.1-beta.1
v17.9.2
v18.*
v18.1.0
v18.2.0
v18.3.0
v18.4.0
v18.4.1
v18.5.0
v18.5.1
v18.6.0
v18.6.1
v18.6.2
v19.*
v19.0.0
v19.0.1
v19.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-37603.json"