An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via a guest name.
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.