Products: 6
    Vulnerabilities: 9
    Known Exploited: 0
    2
    Critical Level Threats
    5
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2018-14729

    The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

    Last Modified: Nov 21, 2024
    Published: May 22, 2019

    CVE-2018-20422

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).

    Last Modified: Nov 21, 2024
    Published: Dec 24, 2018

    CVE-2018-20423

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.

    Last Modified: Nov 21, 2024
    Published: Dec 24, 2018

    CVE-2018-20424

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

    Last Modified: Nov 21, 2024
    Published: Dec 24, 2018

    CVE-2018-18083

    An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.

    Last Modified: Nov 21, 2024
    Published: Oct 09, 2018
    Items Per Page
    Comsenz Vulnerabilities & Security CVEs | CVE-DB