Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 03.07.2024 20:15:04
  • Zuletzt bearbeitet 21.11.2024 09:23:19

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious actor could get the FastImage library to redirect requests to an internal Di...

  • EPSS 0.17%
  • Veröffentlicht 03.07.2024 19:15:04
  • Zuletzt bearbeitet 21.11.2024 09:19:59

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing ...

  • EPSS 0.08%
  • Veröffentlicht 03.07.2024 19:15:04
  • Zuletzt bearbeitet 21.11.2024 09:21:38

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users pre...

  • EPSS 0.24%
  • Veröffentlicht 03.07.2024 18:15:05
  • Zuletzt bearbeitet 26.08.2025 16:58:05

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instan...

  • EPSS 0.11%
  • Veröffentlicht 15.03.2024 20:15:09
  • Zuletzt bearbeitet 26.09.2025 12:50:32

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is patched in the latest stable, beta and tests-passed version of Discour...

  • EPSS 0.09%
  • Veröffentlicht 15.03.2024 20:15:08
  • Zuletzt bearbeitet 26.08.2025 16:56:06

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version o...

  • EPSS 0.09%
  • Veröffentlicht 15.03.2024 20:15:08
  • Zuletzt bearbeitet 26.08.2025 16:56:48

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead ...

  • EPSS 0.11%
  • Veröffentlicht 15.03.2024 20:15:07
  • Zuletzt bearbeitet 09.04.2025 15:36:23

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and ...

  • EPSS 0.06%
  • Veröffentlicht 15.03.2024 20:15:07
  • Zuletzt bearbeitet 26.08.2025 16:36:16

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process...

  • EPSS 0.51%
  • Veröffentlicht 30.01.2024 22:15:53
  • Zuletzt bearbeitet 21.11.2024 08:58:31

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. The v...