Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 01.08.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:04

Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has been included in the latest stable, beta and tests-passed versions of Discourse which rate limits em...

  • EPSS 0.48%
  • Veröffentlicht 27.06.2022 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:53

Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does not adhere to the email domain restriction of an invite link. The impa...

  • EPSS 0.99%
  • Veröffentlicht 14.06.2022 21:15:16
  • Zuletzt bearbeitet 21.11.2024 07:03:48

Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-passed` branches, banner topic data is exposed on login-required sites. This issue is patched in version...

  • EPSS 0.89%
  • Veröffentlicht 07.06.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:03:44

Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-passed` branches, inviting users on sites that use single sign-on could bypass the `must_approve_user...

  • EPSS 0.61%
  • Veröffentlicht 14.04.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:14

Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by anyone that has access to the category. As a result, a normal user is able to see whether a group has read/write permissions in th...

  • EPSS 0.95%
  • Veröffentlicht 14.04.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:10

Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown the crawler view of the site instead of the HTML page. This c...

  • EPSS 0.81%
  • Veröffentlicht 11.04.2022 20:15:20
  • Zuletzt bearbeitet 21.11.2024 06:51:08

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expose groups. When a group with restricted visibility has been used to set the permissions of a category...

  • EPSS 0.93%
  • Veröffentlicht 24.03.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:51:05

Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior in the `beta` branch, and 2.9.0.beta3 and prior in the `tests-passed` branch are vulnerable to a data leak. Users can request an e...

  • EPSS 1.14%
  • Veröffentlicht 15.02.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:48:59

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2 in the `tests-passed` branch, users can trigger a Denial of Service attack by posting a streaming UR...

  • EPSS 1.17%
  • Veröffentlicht 14.01.2022 17:15:13
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group members. By default, a newly created group has its visibility set to public and the group's members ...