← العودة للجدول
CVE-2026-23836
CVE-2026-23836 — VulnCheck: HotCRP is conference review software. A problem introduced in April 20
📅 2026-01-19
🔴 Critical 🔥 No VulnCheck Exploit Web CVSS 9.9

📋 الوصف الكامل

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.

💻 الأنظمة المتأثرة

PHP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-23836

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v3.1

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←