CVE-2024-49765
- EPSS 0.35%
- Veröffentlicht 19.12.2024 20:15:07
- Zuletzt bearbeitet 26.09.2025 12:50:18
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the l...
CVE-2024-52589
- EPSS 0.25%
- Veröffentlicht 19.12.2024 20:15:07
- Zuletzt bearbeitet 26.08.2025 02:16:43
Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unabl...
CVE-2024-52794
- EPSS 0.27%
- Veröffentlicht 19.12.2024 20:15:07
- Zuletzt bearbeitet 26.08.2025 02:14:59
Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for t...
CVE-2024-53991
- EPSS 25.43%
- Veröffentlicht 19.12.2024 20:15:07
- Zuletzt bearbeitet 26.08.2025 02:02:24
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of ...
CVE-2024-47773
- EPSS 1.59%
- Veröffentlicht 08.10.2024 18:15:30
- Zuletzt bearbeitet 26.08.2025 16:58:28
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has ...
CVE-2024-47772
- EPSS 0.33%
- Veröffentlicht 07.10.2024 21:15:18
- Zuletzt bearbeitet 25.09.2025 20:27:29
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This issue only affects sites with CSP disabled. This pro...
CVE-2024-45297
- EPSS 0.32%
- Veröffentlicht 07.10.2024 21:15:17
- Zuletzt bearbeitet 25.09.2025 20:27:02
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users are...
CVE-2024-43789
- EPSS 0.44%
- Veröffentlicht 07.10.2024 21:15:16
- Zuletzt bearbeitet 25.09.2025 20:27:08
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched...
CVE-2024-45051
- EPSS 0.37%
- Veröffentlicht 07.10.2024 21:15:16
- Zuletzt bearbeitet 25.09.2025 20:27:34
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in ...
CVE-2024-39320
- EPSS 0.36%
- Veröffentlicht 30.07.2024 15:15:12
- Zuletzt bearbeitet 21.11.2024 09:27:27
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability i...