Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 15.03.2024 20:15:08
  • Zuletzt bearbeitet 26.08.2025 16:56:48

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead ...

  • EPSS 0.46%
  • Veröffentlicht 15.03.2024 20:15:07
  • Zuletzt bearbeitet 09.04.2025 15:36:23

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and ...

  • EPSS 0.59%
  • Veröffentlicht 15.03.2024 20:15:07
  • Zuletzt bearbeitet 26.08.2025 16:36:16

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process...

  • EPSS 0.49%
  • Veröffentlicht 30.01.2024 22:15:53
  • Zuletzt bearbeitet 21.11.2024 08:58:31

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. The v...

  • EPSS 0.57%
  • Veröffentlicht 12.01.2024 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:54:48

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance to use excessive disk space and also often excessive bandwidth. The is...

  • EPSS 0.52%
  • Veröffentlicht 12.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:31:25

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

  • EPSS 0.32%
  • Veröffentlicht 12.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:32:49

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

  • EPSS 0.98%
  • Veröffentlicht 10.11.2023 16:15:33
  • Zuletzt bearbeitet 21.11.2024 08:29:49

Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 through 3.2.0.beta2 of the `beta` and `tests-passed` branches, Redis memory can be depleted by crafting a s...

  • EPSS 0.69%
  • Veröffentlicht 10.11.2023 16:15:33
  • Zuletzt bearbeitet 21.11.2024 08:29:49

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request forgery. The i...

  • EPSS 0.94%
  • Veröffentlicht 10.11.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:29:49

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox...