Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 28.07.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:02

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple controller actions, Discourse accepts limit params but does not impose any u...

  • EPSS 0.3%
  • Veröffentlicht 28.07.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:03

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized use...

  • EPSS 0.17%
  • Veröffentlicht 28.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:12:26

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in ve...

  • EPSS 0.15%
  • Veröffentlicht 28.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:12:26

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edi...

  • EPSS 0.22%
  • Veröffentlicht 28.07.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:11:46

Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass...

  • EPSS 0.06%
  • Veröffentlicht 14.07.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:09:46

Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is pat...

  • EPSS 0.29%
  • Veröffentlicht 14.07.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:10:39

Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no k...

  • EPSS 0.19%
  • Veröffentlicht 13.07.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:09:47

Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerabilit...

  • EPSS 0.1%
  • Veröffentlicht 13.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:01:28

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has modified their general category permissions, they could be set back to the...

  • EPSS 0.07%
  • Veröffentlicht 13.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:02:38

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the ...