Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 26.02.2026 19:50:56
  • Zuletzt bearbeitet 02.03.2026 21:31:27

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked post visibility checks which allowed unauthorized access to voters details of polls in any post. Versi...

  • EPSS 0.03%
  • Veröffentlicht 26.02.2026 19:25:15
  • Zuletzt bearbeitet 02.03.2026 21:34:00

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able to close, archive and pin topics in private categories they don't have access to. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patc...

  • EPSS 0.03%
  • Veröffentlicht 26.02.2026 19:19:18
  • Zuletzt bearbeitet 02.03.2026 21:36:35

Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insecure Direct Object Reference) in `ReviewableNotesController`. When `enable_category_group_moderation` is enabled, a user belonging ...

  • EPSS 0.04%
  • Veröffentlicht 26.02.2026 15:10:25
  • Zuletzt bearbeitet 02.03.2026 21:37:36

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items endpoint allows any user, including anonymous users, to retrieve private user field values for all user...

  • EPSS 0.03%
  • Veröffentlicht 26.02.2026 15:04:14
  • Zuletzt bearbeitet 02.03.2026 21:51:04

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authenticated user to interact with policies on posts they do not have permission to view. The `PolicyControlle...

  • EPSS 0.04%
  • Veröffentlicht 26.02.2026 15:00:47
  • Zuletzt bearbeitet 02.03.2026 21:52:09

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty strin...

  • EPSS 0.06%
  • Veröffentlicht 26.02.2026 14:58:13
  • Zuletzt bearbeitet 02.03.2026 21:53:56

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentic...

  • EPSS 0.04%
  • Veröffentlicht 28.01.2026 20:11:30
  • Zuletzt bearbeitet 30.01.2026 20:31:42

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensitive information in staff action logs that should be restricted to administrators only. The exposed in...

  • EPSS 0.04%
  • Veröffentlicht 28.01.2026 20:07:21
  • Zuletzt bearbeitet 30.01.2026 20:31:49

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restricted resources (private topics, categories, posts, or hidden tags) were redirecting users to URLs con...

  • EPSS 0.04%
  • Veröffentlicht 28.01.2026 19:51:37
  • Zuletzt bearbeitet 30.01.2026 20:30:18

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, ...