discourse

274 tracked vulnerabilities.

CVE-2025-24972 MEDIUM
Discourse <3.3.4, <3.4.0.beta5 - Info Disclosure
Mar 26, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-24808 MEDIUM
Discourse < 3.3.4 and < 3.4.0.beta5 - Race Condition in Group DM User Addition
Mar 26, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-23023 HIGH
Discourse < 3.3.2 - Cache Poisoning via Anonymous Cache Header Manipulation
Feb 04, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-22602 MEDIUM
Discourse - Stored Cross-Site Scripting via Video Placeholder HTML Element
Feb 04, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-22601 LOW
Discourse < 3.4.0 - Path Traversal via Activate-Account Route
Feb 04, 2025
CVSS 3.1
EPSS 0.00
CVE-2024-53994 MEDIUM
Discourse - Improper Preservation of Permissions in Chat Preferences
Feb 04, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-53851 MEDIUM
Discourse < 3.3.3 and < 3.4.0 - Authenticated Denial of Service via Inline Onebox URL Endpoint
Feb 04, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-53266 MEDIUM
Discourse - Cross-Site Scripting in User Profile Activity Streams
Feb 04, 2025
CVSS 4.3
EPSS 0.00
CVE-2024-56328 MEDIUM
Discourse - Stored Cross-Site Scripting via Malicious Onebox URL
Feb 04, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-56197 LOW
Discourse - Unauthorized Exposure of PM Titles and Metadata via PM Tags Feature
Feb 04, 2025
CVSS 2.2
EPSS 0.00
CVE-2024-55948 HIGH
Discourse < 3.3.2 - Cache Poisoning via Anonymous XHR Request
Feb 04, 2025
CVSS 8.2
EPSS 0.00
CVE-2024-54142 CRITICAL
discourse-ai - Cross-Site Scripting via Shared Bot Conversation HTML Entities
Jan 14, 2025
CVSS 9.0
EPSS 0.00
CVE-2024-53991 HIGH NUCLEI
Discourse - Unauthorized Backup File Access via Nginx Request Manipulation
Dec 19, 2024
CVSS 7.5
EPSS 0.53
CVE-2024-52794 MEDIUM
Discourse - Cross-Site Scripting via Lightbox Thumbnail Click
Dec 19, 2024
CVSS 6.8
EPSS 0.01
CVE-2024-52589 LOW
Discourse - Unauthorized Exposure of User Email via Moderator Dashboard
Dec 19, 2024
CVSS 2.2
EPSS 0.00
CVE-2024-49765 MEDIUM
Discourse - Unauthorized Account Creation via Discourse Connect Bypass
Dec 19, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-47773 HIGH
Discourse < 3.3.2 - Unauthenticated Cache Poisoning via XHR Requests
Oct 08, 2024
CVSS 8.2
EPSS 0.08
CVE-2024-47772 MEDIUM
Discourse < 3.3.2 and < 3.4.0 - Stored Cross-Site Scripting via Chat Message Reply
Oct 07, 2024
CVSS 6.5
EPSS 0.01
CVE-2024-45297 MEDIUM
Discourse < 3.3.2 and < 3.4.0 - Improper Privilege Management
Oct 07, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-45051 HIGH
Discourse < 3.3.2 and < 3.4.0 - Improper Authentication via Maliciously Crafted Email Address
Oct 07, 2024
CVSS 8.2
EPSS 0.00
CVE-2024-43789 HIGH
Discourse < 3.3.1 and < 3.4.0 - Denial of Service via Excessive Post Replies
Oct 07, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-45303 MEDIUM
Discourse Calendar < 0.5 - Cross-Site Scripting in Event Name Rendering
Sep 12, 2024
CVSS 6.1
EPSS 0.01
CVE-2024-21658 MEDIUM
discourse_calendar < 2024-08-28 - Denial of Service via Excessive Region Value Length
Aug 30, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-43408 MEDIUM
discourse-placeholder-theme-component - Stored Cross-Site Scripting via Unsanitized User Input
Aug 20, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-39320 MEDIUM
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
Jul 30, 2024
CVSS 6.1
EPSS 0.01