CVE-2018-19464: Dismall Discuz!
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code.
Affected products
- Dismall Discuz!: version 3.4 only
Published 2018-11-22. Last modified 2026-06-17.