OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108902 (CVSS 7.2)

NVD · officialPublished Oct 11, 2026Risk 23/100

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service.

CVSS
7.2
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source