CVE-2023-45806
- EPSS 1%
- Veröffentlicht 10.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:23
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be...
CVE-2023-45816
- EPSS 0.26%
- Veröffentlicht 10.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:24
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread noti...
CVE-2023-46130
- EPSS 0.7%
- Veröffentlicht 10.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:56
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some theme components allow users to add svgs with unlimited `height` attr...
CVE-2023-43659
- EPSS 0.42%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:24:33
Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in t...
CVE-2023-43814
- EPSS 0.31%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:24:49
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can use the `/polls/grouped_poll_results` endpoint to view the content of options in the poll and the number of votes for groups of po...
CVE-2023-44388
- EPSS 0.53%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:25:47
Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0....
CVE-2023-44391
- EPSS 0.41%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:25:48
Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Disco...
CVE-2023-45131
- EPSS 1.81%
- Veröffentlicht 16.10.2023 22:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:24
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised t...
CVE-2023-45147
- EPSS 0.27%
- Veröffentlicht 16.10.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:26:26
Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custom fields to a topic. The severity of this vulnerability depends on what plugins are installed and how the plugins uses topic custo...
CVE-2023-40588
- EPSS 0.51%
- Veröffentlicht 15.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:19:46
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user could add a 2FA or security key with a carefully crafted name to their ...