CVE-2018-10298: Discuz Discuzx

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content.

Affected products

  • Discuz Discuzx: up to and including x3.4

Published 2018-04-22. Last modified 2026-06-17.