CVE-2018-19464: Dismall Discuz!

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code.

Affected products

Published 2018-11-22. Last modified 2026-06-17.