Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Comsenz

First CVE: Aug 8, 2008Active for: 18 yearsTotal CVEs: 9

Comsenz develops Discuz and related community forum and content-management platforms that are widely deployed, particularly in Asia-Pacific regions, where the vendor's modest product portfolio carries outsized prominence in its market segment. Vulnerabilities affecting these platforms skew toward serious outcomes and frequently acquire public exploit code, clustering around input-validation failures, SQL injection, code injection, and authentication weaknesses that are characteristic of web applications handling user-supplied content and administrative functions. Defenders operating or managing Discuz installations should prioritize security updates and restrict administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Comsenz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2008
17 years ago
Most Recent CVE
May 22, 2019
2,620 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14729HIGH
The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.
May 22, 20198.833NONO
CVE-2018-18084CRITICAL
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
Oct 9, 20189.830NONO
CVE-2018-18083CRITICAL
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
Oct 9, 20189.830NONO
CVE-2009-3185HIGH
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a v
Sep 15, 20097.528NOYES
CVE-2008-6958MEDIUM
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.
Aug 12, 20096.528NOYES
CVE-2008-3554HIGH
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.
Aug 8, 20087.528NOYES
CVE-2018-20423HIGH
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=
Dec 24, 20188.125NONO
CVE-2018-20422HIGH
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to
Dec 24, 20188.125NONO
CVE-2018-20424MEDIUM
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.
Dec 24, 20185.920NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
56%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (66.7%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (33.3%)
High3 (33.3%)
Unknown3 (33.3%)
User Interaction
None6 (66.7%)
Unknown3 (33.3%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None5 (55.6%)
Unknown3 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Comsenz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Comsenz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Comsenz's Products

View all 1 CNAs →

Top CWEs