Comments – wpDiscuz

34 known CVEs 60K+ active installs

Scan My Site Free

UNKNOWN: 34
Known Vulnerabilities 34
CVE-2026-22216 UNKNOWN EPSS 0.2%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the
CVE-2026-22215 UNKNOWN
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthorized actions without nonce validation. Attackers ca
CVE-2026-22210 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpl
CVE-2026-22209 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin a
CVE-2026-22209 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin a
CVE-2026-22209 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin a
CVE-2026-22204 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers
CVE-2026-22203 UNKNOWN EPSS 0.2%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain expor
CVE-2026-22202 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a vali
CVE-2026-22201 UNKNOWN
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Atta
CVE-2026-22199 UNKNOWN EPSS 0.6%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the devi
CVE-2026-22199 UNKNOWN EPSS 0.6%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the devi
CVE-2026-22199 UNKNOWN EPSS 0.6%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the devi
CVE-2026-22199 UNKNOWN EPSS 0.6%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the devi
CVE-2026-22199 UNKNOWN EPSS 0.6%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the devi
CVE-2026-22193 UNKNOWN EPSS 0.2%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious S
CVE-2026-22192 UNKNOWN EPSS 0.2%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localSt
CVE-2026-22192 UNKNOWN EPSS 0.2%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localSt
CVE-2026-22192 UNKNOWN EPSS 0.2%
Published 2026-03-13 · Affected: *
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localSt
CVE-2026-22191 UNKNOWN EPSS 0.3%
Published 2026-03-13 · Affected: *
Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting improper rendering of untrusted input in AngularJS
CVE-2026-22191 UNKNOWN EPSS 0.3%
Published 2026-03-13 · Affected: *
Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting improper rendering of untrusted input in AngularJS
CVE-2026-22191 UNKNOWN EPSS 0.3%
Published 2026-03-13 · Affected: *
Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting improper rendering of untrusted input in AngularJS
CVE-2026-22183 UNKNOWN EPSS 0.1%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting commen
CVE-2026-22182 UNKNOWN EPSS 0.4%
Published 2026-03-13 · Affected: *
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. A
CVE-2023-46309 UNKNOWN EPSS 0.3%
Published 2025-01-02 · Affected: *
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10.
CVE-2023-46309 UNKNOWN EPSS 0.3%
Published 2025-01-02 · Affected: *
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10.
CVE-2023-45760 UNKNOWN EPSS 0.3%
Published 2025-01-02 · Affected: *
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3.
CVE-2023-45760 UNKNOWN EPSS 0.3%
Published 2025-01-02 · Affected: *
Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3.
CVE-2024-2477 UNKNOWN EPSS 0.3%
Published 2024-04-23 · Affected: *
The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions up to, and including, 7.6.15 due to insufficient in
CVE-2024-2477 UNKNOWN EPSS 0.3%
Published 2024-04-23 · Affected: *
The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions up to, and including, 7.6.15 due to insufficient in
CVE-2023-3998 UNKNOWN EPSS 0.3%
Published 2023-10-20 · Affected: *
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes i
CVE-2023-3998 UNKNOWN EPSS 0.3%
Published 2023-10-20 · Affected: *
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes i
CVE-2023-3869 UNKNOWN EPSS 0.3%
Published 2023-10-20 · Affected: *
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This ma
CVE-2023-3869 UNKNOWN EPSS 0.3%
Published 2023-10-20 · Affected: *
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This ma

Is Comments &#8211; wpDiscuz running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free