PatchSiren

pH7Software CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM pH7Software CVE published 2026-09-22

CVE-2026-37604

A remote unauthenticated attacker can bypass IP-based throttling in pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 by sending a different X-Forwarded-For value per request, as the client IP address is resolved from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verification of a trusted proxy. This vulnerability allows an attacker to potentially increase login attempts, highlig [truncated]