Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Cyanpencil

#25286of 56,333
9.9Total CVSS
Vulnerabilities · 1
PT-2026-3476
9.9
2026-01-19
Hotcrp · Hotcrp · CVE-2026-23836
**Name of the Vulnerable Software and Affected Versions** HotCRP version 3.1 **Description** HotCRP is conference review software. A flaw introduced in April 2024 in version 3.1 allows users to trigger the execution of arbitrary PHP code due to inadequately sanitized code generation for HotCRP formulas. The issue grants remote code execution with user privileges. **Recommendations** Update HotCRP to version 3.2.