Comsenz develops Discuz and related community forum and content-management platforms that are widely deployed, particularly in Asia-Pacific regions, where the vendor's modest product portfolio carries outsized prominence in its market segment. Vulnerabilities affecting these platforms skew toward serious outcomes and frequently acquire public exploit code, clustering around input-validation failures, SQL injection, code injection, and authentication weaknesses that are characteristic of web applications handling user-supplied content and administrative functions. Defenders operating or managing Discuz installations should prioritize security updates and restrict administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comsenz over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14729HIGH The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code. | May 22, 2019 | 8.8 | 33 | NO | NO |
CVE-2018-18084CRITICAL An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. | Oct 9, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-18083CRITICAL An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing. | Oct 9, 2018 | 9.8 | 30 | NO | NO |
CVE-2009-3185HIGH SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a v | Sep 15, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6958MEDIUM wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. | Aug 12, 2009 | 6.5 | 28 | NO | YES |
CVE-2008-3554HIGH SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action. | Aug 8, 2008 | 7.5 | 28 | NO | YES |
CVE-2018-20423HIGH Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac= | Dec 24, 2018 | 8.1 | 25 | NO | NO |
CVE-2018-20422HIGH Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to | Dec 24, 2018 | 8.1 | 25 | NO | NO |
CVE-2018-20424MEDIUM Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php. | Dec 24, 2018 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comsenz.
Media articles that mention a CVE ID that affects a product developed by Comsenz — matched by CVE ID, not by vendor name.