VYPR
Critical severity9.9OSV Advisory· Published Jan 19, 2026· Updated Jun 17, 2026

CVE-2026-23836

CVE-2026-23836

Description

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Hotcrp/hotcrp2 versions
    cpe:2.3:a:hotcrp:hotcrp:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hotcrp:hotcrp:*:*:*:*:*:*:*:*range: >=3.0,<3.2
    • (no CPE)range: 3.1 - 3.2
  • Range: v3.0.0, v3.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.