๐Ÿ” CVE Alert

CVE-2026-108904

MEDIUM 6.5

pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication.

CWE CWE-522
Vendor ph7software
Product ph7builder
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for ph7software ph7builder

Be the first to know when new medium vulnerabilities affecting ph7software ph7builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

ph7software / ph7builder
0 < 18.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/52a59da534c7666f7607c8a9b8c42037eb4de66d github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.4.1/_protected/app/system/modules/api/controllers/UserController.php#L161-L206 github.com: https://github.com/pH7Software/pH7-Social-Dating-CMS vulncheck.com: https://www.vulncheck.com/advisories/ph7builder-before-18.5.0-sensitive-data-exposure-via-member-api-usercontroller

Credits

Haluk Baran AKBULUT (CyberMap Group)