CVE-2025-68660
- EPSS 0.22%
- Veröffentlicht 28.01.2026 18:55:11
- Zuletzt bearbeitet 30.01.2026 20:44:35
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated user bypass the ai_discover_persona access controls and gain ongoing DM access to personas that may be...
CVE-2025-68659
- EPSS 0.22%
- Veröffentlicht 28.01.2026 18:51:40
- Zuletzt bearbeitet 30.01.2026 20:44:05
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of service vulnerabilityin the username change functionality at try.discourse.org. The vulnerability allows ...
CVE-2025-68479
- EPSS 0.17%
- Veröffentlicht 28.01.2026 18:34:00
- Zuletzt bearbeitet 30.01.2026 20:43:17
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2,...
CVE-2025-67723
- EPSS 0.21%
- Veröffentlicht 28.01.2026 18:21:35
- Zuletzt bearbeitet 09.02.2026 17:40:37
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a content-security-policy-mitigated cross-site scriptinv vulnerability on the Discourse Math plugin when using its KaTeX variant. This i...
CVE-2025-66488
- EPSS 0.19%
- Veröffentlicht 28.01.2026 18:15:52
- Zuletzt bearbeitet 30.01.2026 20:31:25
Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 affects anyone who uses S3 for uploads. While scripts may be executed, they will only be run in the context of the...
CVE-2025-64528
- EPSS 0.24%
- Veröffentlicht 30.12.2025 16:15:45
- Zuletzt bearbeitet 20.02.2026 17:04:38
Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 20...
CVE-2025-61598
- EPSS 0.27%
- Veröffentlicht 28.10.2025 20:38:54
- Zuletzt bearbeitet 03.12.2025 16:31:01
Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by prox...
CVE-2025-59337
- EPSS 0.27%
- Veröffentlicht 01.10.2025 21:16:43
- Zuletzt bearbeitet 16.10.2025 17:33:47
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or c...
CVE-2025-58054
- EPSS 0.19%
- Veröffentlicht 01.10.2025 19:15:36
- Zuletzt bearbeitet 23.10.2025 15:09:44
Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text...
CVE-2025-58055
- EPSS 0.23%
- Veröffentlicht 01.10.2025 19:15:36
- Zuletzt bearbeitet 23.10.2025 14:15:39
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t ...