Blake Erickson
15 exploits
Active since Jun 2022
Discourse < 3.2.3 and < 3.3.0.beta4 - Unauthorized Email Exposure in Review Queue
CVSS 2.4
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
CVSS 6.1
discourse_calendar < 1.0.1 - Cross-Site Scripting in Event Name Rendering
CVSS 6.5
Discourse <2.8.4-2.9.0.beta5 - Info Disclosure
CVSS 5.3
Discourse BBCode <91478f5 - Code Injection
CVSS 8.8
Discourse < 3.0.1 - Unauthorized Exposure of Sensitive Information via Exclude Tag Parameter
CVSS 4.3
Discourse 3.1.0.beta2-3.1.0.beta3 - Stored Cross-Site Scripting via Chat Message Editing
CVSS 6.5
Discourse Reactions - Exposure of Sensitive Information via Private Topic Reaction Data Leak
CVSS 4.3
Discourse - Denial of Service via Custom Sidebar Section Update
CVSS 6.5
Discourse < 3.0.6 - Race Condition in Invite Link User Creation
CVSS 2.6
Discourse < 3.2.3 and < 3.3.0.beta4 - Unauthorized Email Exposure in Review Queue
CVSS 2.4
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
CVSS 6.1
Discourse Policy <0.1.1 - Info Disclosure
CVSS 3.5