Alan Guo Xiang Tan
25 exploits
Active since Jul 2021
discourse-subscriptions plugin leaking stripe API key in multisite environment
CVSS 5.3
Discourse: Vulnerability in discourse-subscriptions plugin allowing users to self-grant to higher tier subscriptions
CVSS 5.3
Discourse has a bypass of official warnings messages by non-staff users
CVSS 4.3
Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin
Discourse <2.7.7 - Info Disclosure
CVSS 4.3
Discourse < 2.7.8 - Information Disclosure
CVSS 4.3
Discourse - Info Disclosure
CVSS 4.3
Discourse < 2.7.12 - Information Disclosure
CVSS 4.3
Discourse < 2.9.0 - Information Disclosure
CVSS 5.5
Discourse < 2.8.14 - Improper Input Validation
CVSS 5.7
Discourse < 2.8.3 - Information Disclosure
CVSS 5.3
Discourse <2.8.4-2.9.0.beta5 - Auth Bypass
CVSS 2.6
Discourse < 2.8.9 - Improper Input Validation
CVSS 4.3
Discourse <2.8.14 - stable & <3.0.0.beta16 - beta & tests-passed - ...
CVSS 5.7
Discourse <2.8.14, <3.0.0.beta16 - Info Disclosure
CVSS 5.3
Discourse <2.8.14, <3.0.0.beta16 - XSS
CVSS 8.0
Discourse <2.8.14, <3.0.0.beta16 - XSS
CVSS 6.8
Discourse <3.0.1-3.1.0.beta2 - Info Disclosure
CVSS 3.5
Discourse < 3.1.0 - SSRF
CVSS 5.7
Discourse <3.0.6-3.1.0.beta7 - Info Disclosure
CVSS 5.3
Discourse <patched - Auth Bypass
CVSS 9.0
Discourse - DoS
CVSS 5.3
Discourse < 3.2.2 - Improper Input Validation
CVSS 7.5
Discourse <3.4.7-3.5.0.beta.8 - Info Disclosure
CVSS 9.8
Discourse <3.6.2-3.6.0.beta2 - Info Disclosure
CVSS 5.3