MEDIUM
pH7Software
CVE published 2026-09-22
CVE-2026-37604
A remote unauthenticated attacker can bypass IP-based throttling in pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 by sending a different X-Forwarded-For value per request, as the client IP address is resolved from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verification of a trusted proxy. This vulnerability allows an attacker to potentially increase login attempts, highlig [truncated]