Local File Inclusion Vulnerability in Discuz! X5.0 by Discuz!
CVE-2026-49954
Key Information:
- Vendor
Discuz!
- Status
- Vendor
- CVE Published:
- 15 June 2026
Badges
What is CVE-2026-49954?
Discuz! X5.0 versions released between 20260320 and 20260501 exhibit a local file inclusion vulnerability that allows authenticated administrators to exploit improperly sanitized input. By importing plugin configurations containing path traversal sequences, attackers can bypass input validation protections, leading to the execution of malicious code within the web server environment. This vulnerability poses a significant risk, especially when combined with file upload functionalities, resulting in a potential breach of the application's security.
Affected Version(s)
Discuz! X5.0 20260320 <= 20260610
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
