discourse
274 tracked vulnerabilities.
CVE-2022-21642
MEDIUM
Discourse < 2.7.13 - Unauthorized Exposure of Whisper Participants via User Suggestions
Jan 05, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-43850
MEDIUM
Discourse <2.8.0.beta10, <2.7.12 - DoS
Jan 04, 2022
CVSS 6.8
EPSS 0.00
CVE-2021-43840
MEDIUM
message_bus <3.3.7 - Path Traversal
Dec 17, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-43827
MEDIUM
Discourse Footnote < 0.2 - Improper Handling of Nested Tags
Dec 14, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-43794
MEDIUM
Discourse < 2.7.11 - Cache Poisoning Denial of Service for Anonymous Users
Dec 01, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-43793
MEDIUM
Discourse < 2.7.11 - Improper Privilege Management in Polls Feature
Dec 01, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-43792
MEDIUM
Discourse < 2.7.11 - Unauthorized Exposure of Sensitive Tag Notifications
Dec 01, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-41271
MEDIUM
Discourse < 2.7.9 - Exposure of Sensitive Information via Error Response Caching
Nov 15, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-41263
HIGH
rails_multisite <4 - Info Disclosure
Nov 15, 2021
CVSS 8.3
EPSS 0.00
CVE-2021-41163
CRITICAL
Discourse - Remote Code Execution via Unvalidated subscribe_url
Oct 20, 2021
CVSS 10.0
EPSS 0.04
CVE-2021-41140
MEDIUM
Discourse-reactions <0.2 - Info Disclosure
Oct 19, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-41095
MEDIUM
Discourse < 2.7.7 - Cross-Site Scripting via Error Message Rendering
Sep 27, 2021
CVSS 4.2
EPSS 0.00
CVE-2021-41082
HIGH
Discourse < 2021-09-14 - Exposure of Sensitive Information via Private Message Group Handling
Sep 20, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-39161
MEDIUM
Discourse < 2.7.8 - Stored Cross-Site Scripting via Category Name
Aug 26, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-37703
MEDIUM
Discourse < 2.7.8 - Unauthorized Exposure of User Read State
Aug 13, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-37693
MEDIUM
Discourse < 2.7.8 - Insufficient Session Expiration via Email Verification Token
Aug 13, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-37633
HIGH
Discourse < 2.7.8 - Cross-Site Scripting via d-popover Tooltip Rendering
Aug 09, 2021
CVSS 7.4
EPSS 0.00
CVE-2021-32788
MEDIUM
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
Jul 27, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-32764
HIGH
Discourse < 2.7.5 - Cross-Site Scripting via YouTube Onebox Parsing
Jul 15, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-3138
HIGH
Discourse 2.7.0-beta1 - Two-Factor Authentication Bypass via Rate-Limit Bypass
Jan 14, 2021
CVSS 7.5
EPSS 0.03
CVE-2020-24327
MEDIUM
Discourse 2.3.2 and 2.6 - Server-Side Request Forgery via Email Image Upload
Sep 23, 2021
CVSS 5.3
EPSS 0.00
CVE-2019-15515
MEDIUM
Discourse 2.3.2 - Cross-Site Request Forgery via Query String Token
Aug 26, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-1020018
HIGH
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
Jul 29, 2019
CVSS 7.3
EPSS 0.00
CVE-2019-1020017
MEDIUM
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
Jul 29, 2019
CVSS 5.3
EPSS 0.00
Products
discourse 241
calendar 4
discourse-chat 3
discourse_calendar 3
discourse_reactions 2
WP Discourse 1
ai 1
assign 1
discotoc 1
discourse-ai 1
discourse-code-review 1
discourse-encrypt 1
discourse-placeholder-theme-component 1
discourse-policy 1
discourse-reactions 1
discourse_bbcode 1
discourse_footnote 1
discourse_jira 1
discourse_yearly_review 1
group_membership_ip_blocks 1
mermaid 1
message_bus 1
microsoft_authentication 1
patreon 1
rails_multisite 1
reactions 1
Quick Filters