CVE-2021-37703
- EPSS 0.23%
- Veröffentlicht 13.08.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:44
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a user's read state for a topic such as the last read post number and the notification level is exposed.
CVE-2021-37633
- EPSS 0.28%
- Veröffentlicht 09.08.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:15:34
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security ...
CVE-2021-32788
- EPSS 0.39%
- Veröffentlicht 27.07.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:44
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is reve...
CVE-2021-32764
- EPSS 0.24%
- Veröffentlicht 15.07.2021 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:41
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's def...
CVE-2021-3138
- EPSS 2.66%
- Veröffentlicht 14.01.2021 04:15:15
- Zuletzt bearbeitet 21.11.2024 06:20:58
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
CVE-2019-15515
- EPSS 0.16%
- Veröffentlicht 26.08.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:28:54
Discourse 2.3.2 sends the CSRF token in the query string.
CVE-2019-1020018
- EPSS 0.29%
- Veröffentlicht 29.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:12
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
CVE-2019-1020017
- EPSS 0.29%
- Veröffentlicht 29.07.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:11
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.