discuz records
13 published records for vendor discuz.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-5377No exploit | Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.discuz · discuzx · CWE-862 | Critical9.8 | — | 2.1% | Jan 12, 2018 |
36Monitor | CVE-2018-5259No exploit | Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.discuz · discuzx | High8.8 | — | 2.0% | Jan 8, 2018 |
31Monitor | CVE-2008-6957Proof of concept | member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasdiscuz · discuz\! · CWE-264 | High7.5 | — | 2.8% | Aug 12, 2009 |
30Monitor | CVE-2006-5561Proof of concept | SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cdiscuz · discuz gbk | High7.5 | — | 1.1% | Oct 27, 2006 |
30Monitor | CVE-2009-4621Proof of concept | SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands discuz · discuz\! · CWE-89 | High7.5 | — | 1.0% | Jan 18, 2010 |
30Monitor | CVE-2010-4912Proof of concept | SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parametdiscuz · ucenter home · CWE-89 | High7.5 | — | 1.0% | Oct 8, 2011 |
28Monitor | CVE-2024-30884No exploit | Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and odiscuz · discuzx · CWE-79 | High7.1 | — | 0.5% | Apr 11, 2024 |
24Monitor | CVE-2018-5376No exploit | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.discuz · discuzx · CWE-79 | Medium6.1 | — | 0.8% | Jan 12, 2018 |
24Monitor | CVE-2018-5375No exploit | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.discuz · discuzx · CWE-79 | Medium6.1 | — | 0.8% | Jan 12, 2018 |
24Monitor | CVE-2022-45543No exploit | Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or usernamdiscuz · discuzx · CWE-79 | Medium6.1 | — | 0.5% | Feb 15, 2023 |
21Monitor | CVE-2018-5331No exploit | Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.discuz · discuzx · CWE-79 | Medium5.4 | — | 0.6% | Jan 10, 2018 |
21Monitor | CVE-2018-10297No exploit | Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associatediscuz · discuzx · CWE-79 | Medium5.4 | — | 0.5% | Apr 22, 2018 |
21Monitor | CVE-2018-10298No exploit | Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does discuz · discuzx · CWE-79 | Medium5.4 | — | 0.5% | Apr 22, 2018 |
- CVE-2018-537740Plan
Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.
CriticalCVSS 9.8No exploitEPSS 2%discuz · discuzxJan 12, 2018
- CVE-2018-525936Monitor
Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.
HighCVSS 8.8No exploitEPSS 2%discuz · discuzxJan 8, 2018
- CVE-2008-695731Monitor
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpas
HighCVSS 7.5Proof of conceptEPSS 3%discuz · discuz\!Aug 12, 2009
- CVE-2006-556130Monitor
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth c
HighCVSS 7.5Proof of conceptEPSS 1%discuz · discuz gbkOct 27, 2006
- CVE-2009-462130Monitor
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%discuz · discuz\!Jan 18, 2010
- CVE-2010-491230Monitor
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid paramet
HighCVSS 7.5Proof of conceptEPSS 1%discuz · ucenter homeOct 8, 2011
- CVE-2024-3088428Monitor
Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and o
HighCVSS 7.1No exploitEPSS 1%discuz · discuzxApr 11, 2024
- CVE-2018-537624Monitor
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.
MediumCVSS 6.1No exploitEPSS 1%discuz · discuzxJan 12, 2018
- CVE-2018-537524Monitor
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.
MediumCVSS 6.1No exploitEPSS 1%discuz · discuzxJan 12, 2018
- CVE-2022-4554324Monitor
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or usernam
MediumCVSS 6.1No exploitEPSS 1%discuz · discuzxFeb 15, 2023
- CVE-2018-533121Monitor
Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.
MediumCVSS 5.4No exploitEPSS 1%discuz · discuzxJan 10, 2018
- CVE-2018-1029721Monitor
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associate
MediumCVSS 5.4No exploitEPSS 1%discuz · discuzxApr 22, 2018
- CVE-2018-1029821Monitor
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does
MediumCVSS 5.4No exploitEPSS 1%discuz · discuzxApr 22, 2018