References https://zone.ci/aliyun/ali_nonvd/260725.html https://blog.csdn.net/weixin_45949219/article/details/104344854 https://www.sohu.com/a/331734921_290304 https://blog.csdn.net/logan_logan/article/details/119222853 https://github.com/emadshanab/goby_poc5/blob/main/Discuz_ML_3.x_RCE__CNVD_2019_22239.json https://vulners.com/vulnerlab/VULNERABLE:2185 https://blog.csdn.net/woaisk/article/details/95722762 https://cxsecurity.com/cveproduct/19744/42638/discuz_21_ml/ https://github.com/cqr-cryeye-forks/goby-pocs
Related VulnerabilitiesPoCCVE-2026-49952: Discuz! X5.0 - Authentication BypassDiscuz! X5.0 /api/db/dbbak.php 权限绕过漏洞(CVE-2026-49952)wooyun-2010-080723: Discuz Command ExecutionPoCCVE-2020-24186: WordPress wpDiscuz <=7.0.4 - Remote Code ExecutionPoCdiscuz-v72-sqli: Discuz V72 sqliPoCdiscuz-wechat-plugins-unauth: Discuz Wechat Plugins UnauthPoCCVE-2020-13640: wpDiscuz <= 5.3.5 - SQL InjectionDiscuz admin_db.php SQL注入漏洞Discuz 后台弱口令漏洞Discuz 7.x/6.x 全局变量防御绕过导致代码执行Wordpress插件wpDiscuz任意文件上传(未授权)Discuz ML! V3.X 代码注入漏洞(CVE-2019-13956)Discuz 无条件SSRF