CVE-2025-69289
- EPSS 0.03%
- Veröffentlicht 28.01.2026 19:33:58
- Zuletzt bearbeitet 30.01.2026 20:47:35
Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff ac...
CVE-2025-69218
- EPSS 0.04%
- Veröffentlicht 28.01.2026 19:30:28
- Zuletzt bearbeitet 30.01.2026 20:47:31
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all u...
CVE-2025-68934
- EPSS 0.05%
- Veröffentlicht 28.01.2026 19:19:59
- Zuletzt bearbeitet 30.01.2026 20:47:28
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60...
CVE-2025-68933
- EPSS 0.03%
- Veröffentlicht 28.01.2026 19:17:23
- Zuletzt bearbeitet 30.01.2026 20:47:13
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and re...
CVE-2025-68666
- EPSS 0.04%
- Veröffentlicht 28.01.2026 19:14:09
- Zuletzt bearbeitet 30.01.2026 20:47:05
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users with moderation privileges even though moderators should not have access to the archives. Private to...
CVE-2025-68662
- EPSS 0.05%
- Veröffentlicht 28.01.2026 19:12:24
- Zuletzt bearbeitet 30.01.2026 20:44:48
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in...
CVE-2025-68660
- EPSS 0.03%
- Veröffentlicht 28.01.2026 18:55:11
- Zuletzt bearbeitet 30.01.2026 20:44:35
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated user bypass the ai_discover_persona access controls and gain ongoing DM access to personas that may be...
CVE-2025-68659
- EPSS 0.05%
- Veröffentlicht 28.01.2026 18:51:40
- Zuletzt bearbeitet 30.01.2026 20:44:05
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of service vulnerabilityin the username change functionality at try.discourse.org. The vulnerability allows ...
CVE-2025-68479
- EPSS 0.04%
- Veröffentlicht 28.01.2026 18:34:00
- Zuletzt bearbeitet 30.01.2026 20:43:17
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2,...
CVE-2025-67723
- EPSS 0.01%
- Veröffentlicht 28.01.2026 18:21:35
- Zuletzt bearbeitet 09.02.2026 17:40:37
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a content-security-policy-mitigated cross-site scriptinv vulnerability on the Discourse Math plugin when using its KaTeX variant. This i...