Skip to main content

Vendor archive

discourse CVEs

Beta · best-effort

290 CVEs tagged to vendor discourse4 Critical, 46 High, 197 Medium, 42 Low, 1 Unrated.

CVE-2024-35227

Published Jul 3, 2024

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28242

Published Mar 15, 2024

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27100

Published Mar 15, 2024

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing l…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27085

Published Mar 15, 2024

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24827

Published Mar 15, 2024

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24748

Published Mar 15, 2024

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no pub…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24817

Published Feb 22, 2024

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior to version 0.4, event invitee…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23654

Published Feb 21, 2024

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26145

Published Feb 21, 2024

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46241

Published Feb 21, 2024

`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take contr…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24755

Published Feb 1, 2024

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23834

Published Jan 30, 2024

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse i…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21655

Published Jan 12, 2024

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49099

Published Jan 12, 2024

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is req…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-49098

Published Jan 12, 2024

Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48297

Published Jan 12, 2024

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47121

Published Nov 10, 2023

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-47120

Published Nov 10, 2023

Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 through 3.2.0.beta2 of the `beta` an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47119

Published Nov 10, 2023

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, som…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46130

Published Nov 10, 2023

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, som…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45816

Published Nov 10, 2023

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-45806

Published Nov 10, 2023

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45131

Published Oct 16, 2023

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44391

Published Oct 16, 2023

Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This proble…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44388

Published Oct 16, 2023

Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 290 CVEsPage 7 of 12