← Back

Comsenz

comsenz

9 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Discuzx
discuzx
Discuz
discuz
Duomicms
duomicms

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comsenz
1Discuz
Nov 21, 2024
May 22, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.
1Comsenz
1Discuzx
Nov 21, 2024
Dec 24, 2018
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.
1Comsenz
1Discuzx
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.
1Comsenz
1Discuzx
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregist...Show more
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).Show less
1Comsenz
1Duomicms
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
1Comsenz
1Duomicms
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
1Comsenz
1Crazy Star Plugin
Apr 23, 2026
Sep 15, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.
1Comsenz
1Crossday Discuz! Board
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.
1Comsenz
1Discuz
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.