Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Discuz

First CVE: Oct 27, 2006Active for: 20 yearsTotal CVEs: 13
39.6
VTI Score
Medium

Discuz operates a suite of community and discussion forum platforms that, despite a narrow product portfolio, maintains notable prominence in online community infrastructure, particularly in Asian markets. The vendor's disclosures recur around application-layer input-handling issues—cross-site scripting, SQL injection, and authorization weaknesses—that are characteristic of web-based forum software, and frequently acquire public exploit code. Defenders should treat Discuz forum instances as requiring prompt patching, particularly where internet-exposed; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Discuz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 27, 2006
19 years ago
Most Recent CVE
Apr 11, 2024
834 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5377CRITICAL
Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.
Jan 12, 20189.831NONO
CVE-2010-4912HIGH
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.
Oct 8, 20117.531NOYES
CVE-2008-6957HIGH
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predicta
Aug 12, 20097.529NOYES
CVE-2009-4621HIGH
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to
Jan 18, 20107.528NOYES
CVE-2006-5561HIGH
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.
Oct 27, 20067.528NOYES
CVE-2018-5259HIGH
Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.
Jan 8, 20188.826NONO
CVE-2024-30884HIGH
Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and obtain sensitive information via crafted
Apr 11, 20247.120NONO
CVE-2022-45543MEDIUM
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search.
Feb 15, 20236.120NONO
CVE-2018-5375MEDIUM
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.
Jan 12, 20186.120NONO
CVE-2018-10298MEDIUM
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content.
Apr 22, 20185.419NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
46%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (69.2%)
Unknown4 (30.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High0 (0.0%)
Unknown4 (30.8%)
User Interaction
None2 (15.4%)
Unknown4 (30.8%)
Required7 (53.8%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None5 (38.5%)
Unknown4 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Discuz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Discuz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Discuz's Products

View all 1 CNAs →

Top CWEs