Sploitus

CVE-2026-49953

No indexed exploits for CVE-2026-49953 yet

Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attackers can train a custom optical character recognition model against collected CAPTCHA samples to reliably predict challenge text, bypassing protections on login, registration, and other functionality from automated abuse.

Affected products
Discuzx
Fix
Available
CVSS 4.0
6.9 MEDIUM
CVSS 3.1
6.5 MEDIUM
EPSS
0.4% (29th percentile)
Weakness
CWE-804
NVD status
Deferred
Published
2026-06-15
CVE-2026-49953 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-49953 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-49953 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.