VYPR

Discourse Chat

by Discourse (software)

CVEs (3)

  • CVE-2022-31095MedJun 21, 2022
    risk 0.28cvss 4.3epss 0.01

    discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel they do not have access to can view that message using the chat message lookup…

  • CVE-2022-39279MedOct 6, 2022
    risk 0.00cvss 4.3epss 0.00

    discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel's name and description in an unsafe way, allowing staff members to cause an cross site scripting (XSS) attack by inserting unsafe…

  • CVE-2022-36057MedSep 6, 2022
    risk 0.00cvss 5.4epss 0.00

    Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse Chat can be affected by admin users inserting HTML into chat titles and descriptions, causing a Cross-Site Scripting (XSS) attack. Version 0.9 contains a…