Get real-time updates on Telegram
P5Verified
CVE-2026-107637: ph7builder 0 to before 18.5.0
CVE-2026-107637. CVSS 3.1 base score 4.3 (GitHub Advisory Database).
Affected technology
ph7builder · 0 to before 18.5.0
ph7software
Description’s affected range: before 18.5.0
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and availability impact as none; integrity impact as low.
- CWE
- CWE-639
- CCR priority
- 17.2 /100 (P5)
- CVSS 3.1
- 4.3 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N · GitHub Advisory Database
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 18:27:24.781324+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107637.html