David Taylor
21 exploits
Active since Jul 2019
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
CVSS 5.3
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
CVSS 7.3
omniauth-apple <1.0.1 - Info Disclosure
CVSS 7.7
Discourse - Remote Code Execution via Unvalidated subscribe_url
CVSS 10.0
Discourse < 2.7.11 - Improper Privilege Management in Polls Feature
CVSS 4.3
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
CVSS 6.1
Discourse has Stored XSS in AI Triage Automation
CVSS 6.1
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
CVSS 5.3
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
CVSS 7.3
rails_multisite <4 - Info Disclosure
CVSS 8.3
Discourse < 2.7.9 - Exposure of Sensitive Information via Error Response Caching
CVSS 4.8
Discourse < 2.7.11 - Cache Poisoning Denial of Service for Anonymous Users
CVSS 5.3
Discourse < 2.8.3 - Unauthenticated Cache Poisoning via Crawler View Injection
CVSS 5.3
Discourse Patreon < 2022-10-26 - Improper Authentication via Patreon Login
CVSS 9.1
discourse-encrypt < 2023-09-28 - Cross-Site Scripting via Encrypted Topic Title
CVSS 7.2
discourse_calendar < 2023-10-16 - Cross-Site Scripting in Email Preview UI
CVSS 8.0
discourse_jira < 2023-10-01 - Authenticated Server-Side Request Forgery via Jira URL Configuration
CVSS 4.1
Discourse < 3.1.5 and < 3.2.0 - Cross-Site Scripting
CVSS 6.3
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
CVSS 6.1