CVE-2025-54411
- EPSS 0.19%
- Veröffentlicht 19.08.2025 16:41:40
- Zuletzt bearbeitet 20.08.2025 14:40:17
Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.he...
CVE-2025-53102
- EPSS 0.44%
- Veröffentlicht 29.07.2025 19:24:06
- Zuletzt bearbeitet 31.07.2025 18:42:56
Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, w...
CVE-2025-49845
- EPSS 0.3%
- Veröffentlicht 25.06.2025 15:39:01
- Zuletzt bearbeitet 25.08.2025 15:13:54
Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed `whi...
CVE-2025-48954
- EPSS 0.63%
- Veröffentlicht 25.06.2025 14:02:46
- Zuletzt bearbeitet 25.09.2025 20:27:53
Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue. As a workaround, hav...
CVE-2025-48877
- EPSS 0.35%
- Veröffentlicht 09.06.2025 12:36:29
- Zuletzt bearbeitet 25.09.2025 20:27:42
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in the default `allowed_iframes` si...
CVE-2025-48062
- EPSS 0.2%
- Veröffentlicht 09.06.2025 12:33:57
- Zuletzt bearbeitet 26.09.2025 13:05:09
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, certain invites via email may result in HTML injection...
CVE-2025-48053
- EPSS 0.32%
- Veröffentlicht 09.06.2025 12:30:33
- Zuletzt bearbeitet 25.09.2025 20:27:48
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, sending a malicious URL in a PM to a bot user can caus...
CVE-2025-46813
- EPSS 0.34%
- Veröffentlicht 05.05.2025 20:15:21
- Zuletzt bearbeitet 26.09.2025 12:54:49
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some ...
CVE-2025-32376
- EPSS 0.22%
- Veröffentlicht 30.04.2025 14:55:21
- Zuletzt bearbeitet 16.05.2025 16:28:51
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site...
CVE-2025-24808
- EPSS 0.18%
- Veröffentlicht 26.03.2025 14:15:32
- Zuletzt bearbeitet 06.11.2025 22:05:03
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. T...