Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 01.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:47

Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature. A tag group may only allow a certain group (e.g. staff) to view cer...

  • EPSS 0.23%
  • Veröffentlicht 01.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:48

Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users to vote multiple times in a single-option poll. The problem is patched in the latest tests-passed, beta and stable versions of Di...

  • EPSS 0.38%
  • Veröffentlicht 01.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:48

Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-...

  • EPSS 0.29%
  • Veröffentlicht 15.11.2021 22:15:06
  • Zuletzt bearbeitet 21.11.2024 06:25:56

Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patche...

  • EPSS 3.65%
  • Veröffentlicht 20.10.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:38

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest...

  • EPSS 0.22%
  • Veröffentlicht 27.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:27

Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` branch, versions 2.8.0.beta6 and earlier of the `beta` branch, and versions 2.8.0.beta6 and earlier of ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 23.09.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:14:35

Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.

  • EPSS 0.7%
  • Veröffentlicht 20.09.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:24

Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the pr...

  • EPSS 0.26%
  • Veröffentlicht 26.08.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:45

Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks. This is mitigated by Discourse's default Content Security Policy and this vulnerability only affects...

  • EPSS 0.32%
  • Veröffentlicht 13.08.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:15:43

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email veri...