DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
- https://github.com/duxphp/DuxCMS3/issues/4
No PoCs found on GitHub currently.