Discourse

Discourse

280 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 10.08.2026 16:05:11
  • Zuletzt bearbeitet 10.08.2026 17:17:36

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 202...

  • EPSS 0.22%
  • Veröffentlicht 10.08.2026 16:02:56
  • Zuletzt bearbeitet 10.08.2026 19:17:33

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 20...

  • EPSS 0.32%
  • Veröffentlicht 10.08.2026 15:59:53
  • Zuletzt bearbeitet 11.08.2026 03:18:01

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/onebox_handler.rb resolves Chat::Thread by route thread_id independently of the route channel_id before checking whether the u...

  • EPSS 0.39%
  • Veröffentlicht 10.08.2026 15:56:53
  • Zuletzt bearbeitet 10.08.2026 21:17:23

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from SiteSetting.default_navigation_menu_tags without applying DiscourseTaggin...

  • EPSS 0.32%
  • Veröffentlicht 10.08.2026 15:54:35
  • Zuletzt bearbeitet 13.08.2026 18:18:16

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not consistently enforce Guardian.can_see? checks when process...

  • EPSS 0.43%
  • Veröffentlicht 10.08.2026 15:48:30
  • Zuletzt bearbeitet 10.08.2026 17:17:36

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares hostnames and SiteSetting.blocked_onebox_domains entries case-sensitively, allowing an attacker to bypass...

  • EPSS 0.3%
  • Veröffentlicht 10.08.2026 15:41:51
  • Zuletzt bearbeitet 10.08.2026 19:17:33

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.format_for_email because cooked attribute values are reparsed as markup. Crafted Vimeo iframe so...

  • EPSS 0.36%
  • Veröffentlicht 09.07.2026 22:08:52
  • Zuletzt bearbeitet 14.07.2026 20:43:40

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled...

  • EPSS 0.5%
  • Veröffentlicht 09.07.2026 22:05:46
  • Zuletzt bearbeitet 14.07.2026 02:16:55

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scrip...

  • EPSS 0.31%
  • Veröffentlicht 09.07.2026 22:04:50
  • Zuletzt bearbeitet 13.07.2026 15:22:59

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerial...