CVE-2026-107637
pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks.
| CWE | CWE-639 |
| Vendor | ph7software |
| Product | ph7builder |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for ph7software ph7builder
Be the first to know when new medium vulnerabilities affecting ph7software ph7builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
ph7software / ph7builder
0 < 18.5.0
References
github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/e784139b2385ef44d08a1d586c365857dd777ef6 github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.4.1/_protected/app/system/modules/note/controllers/MainController.php#L311-L320 github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS vulncheck.com: https://www.vulncheck.com/advisories/ph7builder-before-18.5.0-improper-authorization-via-note-module-delete-action
Credits
Haluk Baran AKBULUT (CyberMap Group)