Description
pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse.
Published: 2026-10-11
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Form Abuse
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a CAPTCHA bypass that permits an unauthenticated attacker to force form submission by supplying a client‑chosen form ID to PFBC Form::isValid(). This flaw allows the attacker to load a form that normally requires solving a CAPTCHA, such as login or search, and then submit that form ID together with data for other forms like contact, comment, forum, invite or signup. By doing so, the attacker can automate abuse, spamming, or excessive posting, effectively bypassing the intended input validation. The weakness is classified as CWE‑807, indicating an improper neutralization of conditions that allows the attacker to override expected control flow.

Affected Systems

Affected systems are installations of the pH7Builder Social Dating CMS supplied by ph7software. The issue exists in all releases prior to v19.3.0, including the 19.2.0 branch. Forms that rely on the PFBC library for validation—such as contact, comment, forum, invite, signup as well as forms that load a CAPTCHA‑free alternate form—are vulnerable when an attacker can supply an arbitrary form ID.

Risk and Exploitability

The CVSS score of 6.9 suggests a moderate impact. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation. However, the attack vector is likely remote via HTTP/HTTPS; any non‑authenticated user can craft a request containing a form ID, and because the application does not enforce that the ID matches the intended form, an attacker can bypass the CAPTCHA. The risk is primarily operational, enabling automated spam or abuse. Prompt application of the vendor’s patch is the recommended course of action.

Generated by OpenCVE AI on October 11, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pH7Builder to version 19.3.0 or later, which replaces the vulnerable form validation logic.
  • If an upgrade cannot be performed immediately, disable or block form submissions that use externally supplied form IDs, ensuring that only server‑generated identifiers are accepted.
  • Configure logging and monitoring to flag requests containing mismatched form IDs or mass form submissions, and investigate any anomalous activity.

Generated by OpenCVE AI on October 11, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Sun, 11 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse.
Title pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID
Weaknesses CWE-807
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:58:05.502Z

Reserved: 2026-10-11T14:47:10.598Z

Link: CVE-2026-108903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T15:16:56.490

Modified: 2026-10-11T15:16:56.600

Link: CVE-2026-108903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T16:30:17Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision