CVE-2026-108902 - pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link
CVE ID :CVE-2026-108902 Published : Oct. 11, 2026, 3:16 p.m. | 13 minutes ago Description :pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers...