CVE-2018-18084: Comsenz Duomicms

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.

Affected products

Published 2018-10-09. Last modified 2026-06-17.