Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 19.03.2026 22:16:42
  • Zuletzt bearbeitet 24.03.2026 20:53:01

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure ...

  • EPSS 0.41%
  • Veröffentlicht 19.03.2026 22:01:42
  • Zuletzt bearbeitet 24.03.2026 20:41:42

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not apply post-type visibility filtering, allowing regular PM participants to see whisper posts in PM topi...

  • EPSS 0.16%
  • Veröffentlicht 19.03.2026 21:57:27
  • Zuletzt bearbeitet 24.03.2026 20:54:31

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the chat direct message API. First, when creating a direct message channel or adding users to an existing on...

  • EPSS 0.3%
  • Veröffentlicht 19.03.2026 21:52:24
  • Zuletzt bearbeitet 24.03.2026 20:41:24

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticate...

  • EPSS 0.23%
  • Veröffentlicht 19.03.2026 21:49:33
  • Zuletzt bearbeitet 23.03.2026 20:11:17

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right condi...

  • EPSS 0.33%
  • Veröffentlicht 19.03.2026 21:45:13
  • Zuletzt bearbeitet 23.03.2026 20:16:43

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any pri...

  • EPSS 0.31%
  • Veröffentlicht 19.03.2026 21:42:36
  • Zuletzt bearbeitet 23.03.2026 20:17:51

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versi...

  • EPSS 0.27%
  • Veröffentlicht 19.03.2026 21:33:38
  • Zuletzt bearbeitet 23.03.2026 20:18:31

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not...

  • EPSS 0.25%
  • Veröffentlicht 19.03.2026 21:17:43
  • Zuletzt bearbeitet 25.03.2026 21:04:13

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized use...

  • EPSS 0.32%
  • Veröffentlicht 19.03.2026 21:17:09
  • Zuletzt bearbeitet 25.03.2026 00:58:33

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and rend...