← Back to browse · API

CVE-2026-23836

Severity
CRITICAL
CVSS
10.0
EPSS
0.00392
Risk score
40.14
CISA KEV
No
PoC
No
Published
2026-01-19
Modified
2026-01-20
First seen
2026-08-07
Aliases
EUVD-2026-3305
Products
kohler:hotcrp = 3.1
Sources
euvd EUVD-2026-3305

Description

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.

References