CVE-2024-47773
- EPSS 7.85%
- Veröffentlicht 08.10.2024 18:15:30
- Zuletzt bearbeitet 26.08.2025 16:58:28
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has ...
CVE-2024-47772
- EPSS 0.73%
- Veröffentlicht 07.10.2024 21:15:18
- Zuletzt bearbeitet 25.09.2025 20:27:29
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This issue only affects sites with CSP disabled. This pro...
CVE-2024-45297
- EPSS 0.47%
- Veröffentlicht 07.10.2024 21:15:17
- Zuletzt bearbeitet 25.09.2025 20:27:02
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users are...
CVE-2024-43789
- EPSS 0.15%
- Veröffentlicht 07.10.2024 21:15:16
- Zuletzt bearbeitet 25.09.2025 20:27:08
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched...
CVE-2024-45051
- EPSS 0.11%
- Veröffentlicht 07.10.2024 21:15:16
- Zuletzt bearbeitet 25.09.2025 20:27:34
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in ...
CVE-2024-39320
- EPSS 0.87%
- Veröffentlicht 30.07.2024 15:15:12
- Zuletzt bearbeitet 21.11.2024 09:27:27
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability i...
CVE-2024-37165
- EPSS 0.99%
- Veröffentlicht 30.07.2024 15:15:11
- Zuletzt bearbeitet 21.11.2024 09:23:20
Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the defau...
CVE-2024-37299
- EPSS 0.61%
- Veröffentlicht 30.07.2024 15:15:11
- Zuletzt bearbeitet 21.11.2024 09:23:33
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.
CVE-2024-38360
- EPSS 0.35%
- Veröffentlicht 15.07.2024 20:15:03
- Zuletzt bearbeitet 26.08.2025 19:13:33
Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addr...
CVE-2024-36122
- EPSS 0.14%
- Veröffentlicht 03.07.2024 20:15:04
- Zuletzt bearbeitet 21.11.2024 09:21:40
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even whe...