Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 28.01.2026 18:15:52
  • Zuletzt bearbeitet 30.01.2026 20:31:25

Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 affects anyone who uses S3 for uploads. While scripts may be executed, they will only be run in the context of the...

  • EPSS 0.04%
  • Veröffentlicht 30.12.2025 16:15:45
  • Zuletzt bearbeitet 20.02.2026 17:04:38

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 20...

  • EPSS 0.07%
  • Veröffentlicht 28.10.2025 20:38:54
  • Zuletzt bearbeitet 03.12.2025 16:31:01

Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by prox...

  • EPSS 0.03%
  • Veröffentlicht 01.10.2025 21:16:43
  • Zuletzt bearbeitet 16.10.2025 17:33:47

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or c...

  • EPSS 0.03%
  • Veröffentlicht 01.10.2025 19:15:36
  • Zuletzt bearbeitet 23.10.2025 15:09:44

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text...

  • EPSS 0.05%
  • Veröffentlicht 01.10.2025 19:15:36
  • Zuletzt bearbeitet 23.10.2025 14:15:39

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t ...

  • EPSS 0.03%
  • Veröffentlicht 19.08.2025 16:41:40
  • Zuletzt bearbeitet 20.08.2025 14:40:17

Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.he...

  • EPSS 0.07%
  • Veröffentlicht 29.07.2025 19:24:06
  • Zuletzt bearbeitet 31.07.2025 18:42:56

Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, w...

  • EPSS 0.08%
  • Veröffentlicht 25.06.2025 15:39:01
  • Zuletzt bearbeitet 25.08.2025 15:13:54

Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed `whi...

  • EPSS 15.58%
  • Veröffentlicht 25.06.2025 14:02:46
  • Zuletzt bearbeitet 25.09.2025 20:27:53

Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue. As a workaround, hav...