Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 17.03.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 07:46:33

Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of w...

  • EPSS 0.21%
  • Veröffentlicht 17.03.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 07:50:38

Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue i...

  • EPSS 0.31%
  • Veröffentlicht 16.03.2023 21:15:13
  • Zuletzt bearbeitet 21.11.2024 07:47:08

Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all pers...

  • EPSS 0.11%
  • Veröffentlicht 04.03.2023 01:15:10
  • Zuletzt bearbeitet 21.11.2024 07:50:15

Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `...

  • EPSS 0.88%
  • Veröffentlicht 08.02.2023 20:15:25
  • Zuletzt bearbeitet 21.11.2024 07:49:14

Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of D...

  • EPSS 0.24%
  • Veröffentlicht 03.02.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 07:46:32

Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse...

  • EPSS 0.34%
  • Veröffentlicht 28.01.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:32

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with t...

  • EPSS 0.35%
  • Veröffentlicht 28.01.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:32

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, the contents of latest/top routes for restricted tags can be accessed by unauthorized users. Thi...

  • EPSS 0.4%
  • Veröffentlicht 28.01.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:33

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, a malicious user can cause a regular expression denial of service using a carefully craf...

  • EPSS 0.26%
  • Veröffentlicht 28.01.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:33

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were ...