Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 30.07.2024 15:15:11
  • Zuletzt bearbeitet 21.11.2024 09:23:20

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the defau...

  • EPSS 0.6%
  • Veröffentlicht 30.07.2024 15:15:11
  • Zuletzt bearbeitet 21.11.2024 09:23:33

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

  • EPSS 0.47%
  • Veröffentlicht 15.07.2024 20:15:03
  • Zuletzt bearbeitet 26.08.2025 19:13:33

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addr...

  • EPSS 0.37%
  • Veröffentlicht 03.07.2024 20:15:04
  • Zuletzt bearbeitet 21.11.2024 09:21:40

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even whe...

  • EPSS 0.35%
  • Veröffentlicht 03.07.2024 20:15:04
  • Zuletzt bearbeitet 21.11.2024 09:23:19

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious actor could get the FastImage library to redirect requests to an internal Di...

  • EPSS 0.33%
  • Veröffentlicht 03.07.2024 19:15:04
  • Zuletzt bearbeitet 21.11.2024 09:19:59

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing ...

  • EPSS 0.42%
  • Veröffentlicht 03.07.2024 19:15:04
  • Zuletzt bearbeitet 21.11.2024 09:21:38

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users pre...

  • EPSS 0.59%
  • Veröffentlicht 03.07.2024 18:15:05
  • Zuletzt bearbeitet 26.08.2025 16:58:05

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instan...

  • EPSS 0.49%
  • Veröffentlicht 15.03.2024 20:15:09
  • Zuletzt bearbeitet 26.09.2025 12:50:32

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is patched in the latest stable, beta and tests-passed version of Discour...

  • EPSS 0.57%
  • Veröffentlicht 15.03.2024 20:15:08
  • Zuletzt bearbeitet 26.08.2025 16:56:06

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version o...