Discourse

Discourse

188 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 12.01.2024 21:15:11
  • Zuletzt bearbeitet 21.11.2024 08:54:48

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to cause a Discourse instance to use excessive disk space and also often excessive bandwidth. The is...

  • EPSS 0.18%
  • Veröffentlicht 12.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:31:25

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

  • EPSS 0.29%
  • Veröffentlicht 12.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:32:49

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

  • EPSS 0.3%
  • Veröffentlicht 10.11.2023 16:15:33
  • Zuletzt bearbeitet 21.11.2024 08:29:49

Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 through 3.2.0.beta2 of the `beta` and `tests-passed` branches, Redis memory can be depleted by crafting a s...

  • EPSS 0.4%
  • Veröffentlicht 10.11.2023 16:15:33
  • Zuletzt bearbeitet 21.11.2024 08:29:49

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request forgery. The i...

  • EPSS 11.84%
  • Veröffentlicht 10.11.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:29:49

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox...

  • EPSS 3.32%
  • Veröffentlicht 10.11.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 08:27:23

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be...

  • EPSS 0.17%
  • Veröffentlicht 10.11.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 08:27:24

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread noti...

  • EPSS 0.19%
  • Veröffentlicht 10.11.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 08:27:56

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some theme components allow users to add svgs with unlimited `height` attr...

  • EPSS 0.63%
  • Veröffentlicht 16.10.2023 22:15:12
  • Zuletzt bearbeitet 21.11.2024 08:24:33

Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in t...