{"id":"CVE-2026-37604","details":"pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request","modified":"2026-09-24T03:45:22.812022782Z","published":"2026-09-22T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37604.json"},"references":[{"type":"WEB","url":"https://ph7builder.com"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37604.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-37604"},{"type":"PACKAGE","url":"https://github.com/pH7Software/pH7-Social-Dating-CMS"},{"type":"ARTICLE","url":"https://cybermapgroup.com/en/blog/admin-brute-force-protection-bypass-chain-in-ph7builder"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ph7software/ph7-social-dating-cms","events":[{"introduced":"0"},{"fixed":"1cadc7dc1a08c8e24a3c5b6a3a34526281789cba"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"18.2.0"}]}}],"versions":["v18.1.0","v17.9.2","17.9.2-beta.2","17.9.2-beta.1","v17.9.1-beta.1","v17.9.1","v17.9.0","18.0.0-beta.2","18.0.0-beta.1","17.2.0","17.2.0-rc.2","17.2.0-rc.1","17.2.0-beta.1","17.1.8","17.1.8.beta.2","17.1.8.beta.1","17.1.2","17.1.0","17.0.1","17.0.0","v17.0.0","17.0.0-beta.3","v17.0.0-beta.2","17.0.0-beta.2","16.5.0.beta.1","16.3.2","16.3.0-beta.1","16.3.0","16.2.2","16.2.0-beta.1","16.2.0","16.1.0","16.1.0-beta.1","16.0.2-beta.1","16.0.0","16.0.0-rc.3","16.0.0-rc.2","16.0.0-rc.1","16.0.0-beta.2","16.0.0-beta.1","15.4.0","15.4.0-beta.2","15.4.0-beta.1","15.3.0","15.3.0-rc.3","15.3.0-rc.1","15.2.0","15.1.8","15.1.7","15.1.6","15.1.0","15.1.0-rc2","15.1.0-rc","15.1.0-beta","15.0.0","15.0.0-rc","15.0.0-beta2","15.0.0-beta1","14.9.0","14.9.0-rc2","14.9.0-rc","14.8.9","14.8.8","14.8.8-rc2","14.8.8-rc","14.8.0","14.7.0","14.3.6","14.3.4-rc","14.3.0","14.0.0","14.0.0-rc3","14.0.0-rc2","14.0.0-rc","12.9.9","12.9.8","untagged-de05a9b7f66bb64ad418","12.9.0","12.6.1","12.6.5","12.5.9","12.3.5","12.6.0","12.3.0","12.1.2","12.1.0","12.0.0","10.2.0","10.0.8","8.0.6","8.0.4","8.0.3","8.0.2","7.1.3","7.0.01","7.0.0","6.0.13","6.0.9","6.0.1","6.0.0","5.0.0","4.0.0","3.1.0","3.0.0","2.0.9","2.0.4","1.4.2","1.4.1","1.4.0","1.3.9","1.3.8","1.3.7","1.3.6","1.3.5","1.3.0","1.2.9","1.2.8","1.2.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-37604.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}