MinorCritical vulnerability
CVE-2026-108902 (CVSS 7.2)
NVD · officialPublished Oct 11, 2026Risk 23/100
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service.
Technical details
CVSS
7.2
AV:NetworkAC:LowPR:LowUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source