High severity7.2NVD Advisory· Published Sep 2, 2022· Updated Jun 17, 2026
CVE-2022-37458
CVE-2022-37458
Description
Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<=2.8.7+ 2 more
- (no CPE)range: <=2.8.7
- cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <=2.8.7
- (no CPE)
Patches
Vulnerability mechanics
References
3- github.com/discourse/discourse/security/advisories/GHSA-q2rg-m477-8wg7nvdThird Party Advisory
- github.com/discourse/discourse/tagsnvdRelease NotesThird Party Advisory
- www.enisa.europa.eu/topics/threat-risk-management/vulnerability-disclosurenvdThird Party Advisory
News mentions
0No linked articles in our index yet.