Alan Guo Xiang Tan
36 exploits
Active since Jul 2021
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
CVSS 4.3
Discourse < 2021-09-14 - Exposure of Sensitive Information via Private Message Group Handling
CVSS 7.5
Discourse <2.8.4-2.9.0.beta5 - Auth Bypass
CVSS 2.6
Discourse <2.8.14 - stable & <3.0.0.beta16 - beta & tests-passed - ...
CVSS 5.7
Discourse < 3.2.3 - Denial of Service via Malicious Onebox URL
CVSS 7.5
Discourse <3.4.7-3.5.0.beta.8 - Info Disclosure
CVSS 9.8
Discourse <3.6.2-3.6.0.beta2 - Info Disclosure
CVSS 5.3
Discourse Post Actions API - Non-Staff Warning Authorization Bypass
CVSS 4.3
Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin
CVSS 6.5
Discourse Post Actions API - Non-Staff Warning Authorization Bypass
CVSS 4.3
Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin
CVSS 6.5
discourse-subscriptions plugin leaking stripe API key in multisite environment
CVSS 5.3
Discourse Subscriptions Plugin - Higher-Tier Subscription Privilege Escalation
CVSS 5.3
Discourse Post Actions API - Non-Staff Warning Authorization Bypass
CVSS 4.3
Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin
CVSS 6.5
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
CVSS 4.3
Discourse < 2.7.8 - Unauthorized Exposure of User Read State
CVSS 4.3
Discourse < 2.7.11 - Improper Privilege Management in Polls Feature
CVSS 4.3
Discourse < 2.7.13 - Unauthorized Exposure of Sensitive Group Information via Advanced Search
CVSS 4.3
Discourse < 2.9.0 - Unauthorized Exposure of Sensitive Information via Malicious URL Embedding
CVSS 5.5
Discourse < 2.8.14 - Input Validation Bypass via HTML Comments
CVSS 5.7
Discourse < 2.8.3 - Unauthorized Group Name Exposure via Category Permissions
CVSS 5.3
Discourse <2.8.4-2.9.0.beta5 - Auth Bypass
CVSS 2.6
Discourse < 2.8.9 - Denial of Service via Large Payload in User Profile Fields
CVSS 4.3
Discourse <2.8.14 - stable & <3.0.0.beta16 - beta & tests-passed - ...
CVSS 5.7