Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 15.09.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:20:26

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, importing a remote theme loads their assets into memory without enforcing limits for fil...

  • EPSS 0.51%
  • Veröffentlicht 15.09.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:20:26

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin could create extremely large icons sprites, which would then be cached...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 15.09.2023 20:15:09
  • Zuletzt bearbeitet 21.11.2024 08:14:05

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys whic...

  • EPSS 0.58%
  • Veröffentlicht 28.07.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:13:41

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in...

  • EPSS 0.53%
  • Veröffentlicht 28.07.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:02

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple controller actions, Discourse accepts limit params but does not impose any u...

  • EPSS 0.39%
  • Veröffentlicht 28.07.2023 16:15:12
  • Zuletzt bearbeitet 21.11.2024 08:14:03

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized use...

  • EPSS 0.24%
  • Veröffentlicht 28.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:12:26

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in ve...

  • EPSS 0.45%
  • Veröffentlicht 28.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:12:26

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edi...

  • EPSS 0.32%
  • Veröffentlicht 28.07.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:11:46

Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass...

  • EPSS 0.35%
  • Veröffentlicht 14.07.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:09:46

Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is pat...