Martin Brennan
11 exploits
Active since Mar 2022
Discourse < 3.1.3 and < 3.2.0.beta3 - Unauthorized Access to Bookmarkable Resources via Notification Edge Case
CVSS 3.3
Discourse: XSS on category description update via API
CVSS 5.4
Discourse < 2.8.2 - Unauthorized Exposure of Secure Category Names in User Activity Export
CVSS 4.3
Discourse < 2.8.9 - Denial of Service via Large Payload in User Profile Fields
CVSS 4.3
Discourse < 2.8.10 - Unauthorized Private Message Topic Access via Invitation Redemption
CVSS 6.5
Discourse < 2.9.0.beta13 - Denial of Service via Unlimited Chat Message Length
CVSS 3.5
Discourse < 2.8.12 - Unauthorized Sensitive Information Exposure via Topic Notifications
CVSS 3.5
Discourse < 3.1.3 and < 3.2.0.beta3 - Unauthorized Access to Bookmarkable Resources via Notification Edge Case
CVSS 3.3
Discourse-reactions - Info Disclosure
CVSS 4.3
Discourse < 3.5.0 - Stored Cross-Site Scripting via Welcome Banner Username
CVSS 5.4
Discourse < 3.5.1 - Stored Cross-Site Scripting via Chat Channel and Thread Title Quote
CVSS 3.5