CVE-2018-10297: Discuz Discuzx

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.

Affected products

  • Discuz Discuzx: up to and including x3.4

Published 2018-04-22. Last modified 2026-06-17.