VYPR

Calendar

by Discourse (software)

CVEs (4)

  • CVE-2024-45303MedSep 12, 2024
    risk 0.00cvss 6.1epss 0.00

    Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content…

  • CVE-2024-24817MedFeb 22, 2024
    risk 0.00cvss 4.3epss 0.00

    Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior to version 0.4, event invitees created in topics in private categories or PMs (private messages) can be retrieved by anyone, even…

  • CVE-2024-26145MedFeb 21, 2024
    risk 0.00cvss 6.5epss 0.00

    Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a request to update their attendance. This problem is resolved in commit…

  • CVE-2022-41913MedNov 14, 2022
    risk 0.00cvss 4.3epss 0.00

    Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Members of private groups or public groups with private members can be listed by users, who can create and edit post events. This…