Skip to main content

Vendor archive

discourse CVEs

Beta · best-effort

290 CVEs tagged to vendor discourse4 Critical, 46 High, 197 Medium, 42 Low, 1 Unrated.

CVE-2023-43814

Published Oct 16, 2023

Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-43659

Published Oct 16, 2023

Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43658

Published Oct 16, 2023

dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Improper escaping of event tit…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45147

Published Oct 16, 2023

Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custom fields to a topic. The severity of this vulnerability dep…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44384

Published Oct 6, 2023

Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by set…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43657

Published Sep 28, 2023

discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41043

Published Sep 15, 2023

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41042

Published Sep 15, 2023

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, importing a remot…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40588

Published Sep 15, 2023

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38706

Published Sep 15, 2023

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38685

Published Jul 28, 2023

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38684

Published Jul 28, 2023

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple contr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38498

Published Jul 28, 2023

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37906

Published Jul 28, 2023

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37904

Published Jul 28, 2023

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than p…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37467

Published Jul 28, 2023

Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36818

Published Jul 14, 2023

Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patch…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36466

Published Jul 14, 2023

Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title len…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36473

Published Jul 13, 2023

Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34250

Published Jun 13, 2023

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32301

Published Jun 13, 2023

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicat…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32061

Published Jun 13, 2023

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31142

Published Jun 13, 2023

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has mod…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-30611

Published Apr 19, 2023

Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were perfor…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30606

Published Apr 18, 2023

Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the `SiteSetting` class, notabl…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 290 CVEsPage 8 of 12