Discuz! X5.0是Discuz!团队的一款PHP网络论坛程序。 Discuz! X5.0 20260320版本至20260610版本存在代码注入漏洞,该漏洞源于导入包含路径遍历序列的特制插件配置,允许已认证管理员通过触发插件安装异常绕过清理导致恶意路径传递至include函数,结合文件上传功能执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Discuz! | Discuz! X5.0 | 20260320≤ 20260610 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Discuz! | Discuz! X5.0 | 20260320 ~ 20260610 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49952 | 9.1 CRITICAL | Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle |
| CVE-2026-49953 | 6.5 MEDIUM | Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set |
No comments yet