Penar Musaraj
22 exploits
Active since Jan 2023
Discourse < 3.0.1 and 3.1.0.beta2 - Unauthorized Sensitive Information Exposure via Tag Topic Count
CVSS 4.3
Discourse <3.1.3-3.2.0.beta3 - Info Disclosure
CVSS 4.3
Discourse 3.5.0.beta4 - Unauthenticated Exposure of Sensitive Information via Homepage Content Leak
CVSS 5.8
Discourse leaks PM post edits to moderators
CVSS 2.7
Discourse has stored click‑based XSS via Graphviz SVG javascript: links
CVSS 4.4
Discourse has Improper Authorization in "Post Edits" Report For Moderators
CVSS 2.2
Discourse leaks PM post edits to moderators
CVSS 2.7
Discourse has stored click‑based XSS via Graphviz SVG javascript: links
CVSS 4.4
Discourse has Improper Authorization in "Post Edits" Report For Moderators
CVSS 2.2
Discourse vulnerable to HTML injection via prohibited iframe URLs
CVSS 4.1
Discourse leaks PM post edits to moderators
CVSS 2.7
Discourse has stored click‑based XSS via Graphviz SVG javascript: links
CVSS 4.4
Discourse has Improper Authorization in "Post Edits" Report For Moderators
CVSS 2.2
Discourse <2.8.14, <3.0.0.beta16 - Info Disclosure
CVSS 5.3
Discourse < 3.0.1 - Unauthorized Access to Restricted Tag Content
CVSS 5.3
Discourse < 3.0.1 - Regular Expression Denial of Service via User Agent
CVSS 8.6
Discourse < 3.0.1 and 3.1.0.beta2 - Unauthorized Sensitive Information Exposure via Tag Topic Count
CVSS 4.3
Discourse < 3.0.6 - Denial of Service via Crafted Edit Reason
CVSS 4.3
Discourse <3.1.3-3.2.0.beta3 - Info Disclosure
CVSS 4.3
Discourse-reactions - Info Disclosure
CVSS 3.5
Discourse < 3.2.0 and < 3.3.0 - Uncontrolled Resource Consumption via Invite Route Parameters
CVSS 6.5
Discourse 3.5.0.beta4 - Unauthenticated Exposure of Sensitive Information via Homepage Content Leak
CVSS 5.8