Roman Rizzi
13 exploits
Active since Aug 2022
Discourse < 3.1.3 and < 3.2.0.beta3 - HTML Injection via Onebox Engine
CVSS 5.3
Discourse < 3.1.3 and < 3.2.0.beta3 - HTML Injection via Onebox Engine
CVSS 5.3
Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox
CVSS 6.1
Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox
CVSS 6.1
Discourse has Stored XSS in AI Triage Automation
CVSS 6.1
Discourse: Category group moderators can perform actions on topics in restricted categories without read access
CVSS 5.4
Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox
CVSS 6.1
Discourse has Stored XSS in AI Triage Automation
CVSS 6.1
Discourse < 2.8.7 - Denial of Service via Malicious Static Asset Request
CVSS 5.3
Discourse < 2.8.6 - Unauthenticated Mass Spam Email via Email Activation Route
CVSS 6.5
discourse-chat < 0.9 - Authenticated Stored Cross-Site Scripting via Channel Name and Description
CVSS 4.3
discourse-ai < 2024-02-21 - Server-Side Request Forgery via AI Service Interaction
CVSS 4.1
Discourse < 3.5.1 - Authenticated Improper Access Control via AI Suggestion Endpoint Topic ID Manipulation
CVSS 4.3