Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-23836

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.8%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2026-23836
  • Hotcrp » Hotcrp » Version: 3.0
    cpe:2.3:a:hotcrp:hotcrp:3.0
  • Hotcrp » Hotcrp » Version: 3.0.0
    cpe:2.3:a:hotcrp:hotcrp:3.0.0
  • Hotcrp » Hotcrp » Version: 3.1
    cpe:2.3:a:hotcrp:hotcrp:3.1


Contact Us

Shodan ® - All rights reserved