Discourse

Discourse

252 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 26.02.2026 14:58:13
  • Zuletzt bearbeitet 02.03.2026 21:53:56

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentic...

  • EPSS 0.26%
  • Veröffentlicht 28.01.2026 20:11:30
  • Zuletzt bearbeitet 30.01.2026 20:31:42

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensitive information in staff action logs that should be restricted to administrators only. The exposed in...

  • EPSS 0.25%
  • Veröffentlicht 28.01.2026 20:07:21
  • Zuletzt bearbeitet 30.01.2026 20:31:49

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restricted resources (private topics, categories, posts, or hidden tags) were redirecting users to URLs con...

  • EPSS 0.22%
  • Veröffentlicht 28.01.2026 19:51:37
  • Zuletzt bearbeitet 30.01.2026 20:30:18

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, ...

  • EPSS 0.16%
  • Veröffentlicht 28.01.2026 19:33:58
  • Zuletzt bearbeitet 30.01.2026 20:47:35

Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff ac...

  • EPSS 0.2%
  • Veröffentlicht 28.01.2026 19:30:28
  • Zuletzt bearbeitet 30.01.2026 20:47:31

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all u...

  • EPSS 0.24%
  • Veröffentlicht 28.01.2026 19:19:59
  • Zuletzt bearbeitet 30.01.2026 20:47:28

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60...

  • EPSS 0.15%
  • Veröffentlicht 28.01.2026 19:17:23
  • Zuletzt bearbeitet 30.01.2026 20:47:13

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and re...

  • EPSS 0.24%
  • Veröffentlicht 28.01.2026 19:14:09
  • Zuletzt bearbeitet 30.01.2026 20:47:05

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users with moderation privileges even though moderators should not have access to the archives. Private to...

  • EPSS 0.3%
  • Veröffentlicht 28.01.2026 19:12:24
  • Zuletzt bearbeitet 30.01.2026 20:44:48

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in...