📦 Hotcrp

by Hotcrp

🔍 What is Hotcrp?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-23836

CRITICAL CVSS 9.9 Jan 19, 2026

CVE-2026-23836 is a critical remote code execution vulnerability in HotCRP conference review software. It allows authenticated users to execute arbitrary PHP code through inadequately sanitized formul...

CVE-2026-25156

HIGH CVSS 7.3 Jan 30, 2026

HotCRP conference review software versions from October 2025 through January 2026 incorrectly delivered all document types with inline Content-Disposition, causing them to render in browsers instead o...

CVE-2026-23878

MEDIUM CVSS 6.5 Jan 19, 2026

This vulnerability in HotCRP conference review software allows authors with at least one submission to download any documents (PDFs, attachments) from any submission on the site, bypassing intended ac...