discourse

274 tracked vulnerabilities.

CVE-2022-21642 MEDIUM
Discourse < 2.7.13 - Unauthorized Exposure of Whisper Participants via User Suggestions
Jan 05, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-43850 MEDIUM
Discourse <2.8.0.beta10, <2.7.12 - DoS
Jan 04, 2022
CVSS 6.8
EPSS 0.00
CVE-2021-43840 MEDIUM
message_bus <3.3.7 - Path Traversal
Dec 17, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-43827 MEDIUM
Discourse Footnote < 0.2 - Improper Handling of Nested Tags
Dec 14, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-43794 MEDIUM
Discourse < 2.7.11 - Cache Poisoning Denial of Service for Anonymous Users
Dec 01, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-43793 MEDIUM
Discourse < 2.7.11 - Improper Privilege Management in Polls Feature
Dec 01, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-43792 MEDIUM
Discourse < 2.7.11 - Unauthorized Exposure of Sensitive Tag Notifications
Dec 01, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-41271 MEDIUM
Discourse < 2.7.9 - Exposure of Sensitive Information via Error Response Caching
Nov 15, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-41263 HIGH
rails_multisite <4 - Info Disclosure
Nov 15, 2021
CVSS 8.3
EPSS 0.00
CVE-2021-41163 CRITICAL
Discourse - Remote Code Execution via Unvalidated subscribe_url
Oct 20, 2021
CVSS 10.0
EPSS 0.04
CVE-2021-41140 MEDIUM
Discourse-reactions <0.2 - Info Disclosure
Oct 19, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-41095 MEDIUM
Discourse < 2.7.7 - Cross-Site Scripting via Error Message Rendering
Sep 27, 2021
CVSS 4.2
EPSS 0.00
CVE-2021-41082 HIGH
Discourse < 2021-09-14 - Exposure of Sensitive Information via Private Message Group Handling
Sep 20, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-39161 MEDIUM
Discourse < 2.7.8 - Stored Cross-Site Scripting via Category Name
Aug 26, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-37703 MEDIUM
Discourse < 2.7.8 - Unauthorized Exposure of User Read State
Aug 13, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-37693 MEDIUM
Discourse < 2.7.8 - Insufficient Session Expiration via Email Verification Token
Aug 13, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-37633 HIGH
Discourse < 2.7.8 - Cross-Site Scripting via d-popover Tooltip Rendering
Aug 09, 2021
CVSS 7.4
EPSS 0.00
CVE-2021-32788 MEDIUM
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
Jul 27, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-32764 HIGH
Discourse < 2.7.5 - Cross-Site Scripting via YouTube Onebox Parsing
Jul 15, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-3138 HIGH
Discourse 2.7.0-beta1 - Two-Factor Authentication Bypass via Rate-Limit Bypass
Jan 14, 2021
CVSS 7.5
EPSS 0.03
CVE-2020-24327 MEDIUM
Discourse 2.3.2 and 2.6 - Server-Side Request Forgery via Email Image Upload
Sep 23, 2021
CVSS 5.3
EPSS 0.00
CVE-2019-15515 MEDIUM
Discourse 2.3.2 - Cross-Site Request Forgery via Query String Token
Aug 26, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-1020018 HIGH
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
Jul 29, 2019
CVSS 7.3
EPSS 0.00
CVE-2019-1020017 MEDIUM
Discourse <2.3.0, <2.4.0.beta3 - Info Disclosure
Jul 29, 2019
CVSS 5.3
EPSS 0.00