Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse. | |
| Title | pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID | |
| Weaknesses | CWE-807 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T14:58:05.502Z
Reserved: 2026-10-11T14:47:10.598Z
Link: CVE-2026-108903
No data.
Status : Deferred
Published: 2026-10-11T15:16:56.490
Modified: 2026-10-11T15:16:56.600
Link: CVE-2026-108903
No data.
OpenCVE Enrichment
No data.