VYPR

Discourse

by Discourse (software)

Source repositories

CVEs (285)

  • CVE-2025-61598MedOct 28, 2025
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to…

  • CVE-2025-59337MedOct 1, 2025
    risk 0.00cvss 6.8epss 0.00

    Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites.…

  • CVE-2025-58055MedOct 1, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to…

  • CVE-2025-58054LowOct 1, 2025
    risk 0.00cvss 3.5epss 0.00

    Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed…

  • CVE-2025-54411MedAug 19, 2025
    risk 0.00cvss 5.4epss 0.00

    Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.logged_in_members site…

  • CVE-2025-53102CriJul 29, 2025
    risk 0.00cvss 9.8epss 0.00

    Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The…

  • CVE-2025-46813MedMay 5, 2025
    risk 0.00cvss 5.8epss 0.00

    Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some content on the site's…

  • CVE-2025-32376MedApr 30, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been…

  • CVE-2025-24808MedMar 26, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. The requests might all go…

  • CVE-2024-53851MedFeb 4, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enforcing limits on the number of URLs that it accepted, allowing a malicious user to inflict denial of service on some parts of the…

  • CVE-2024-37299MedJul 30, 2024
    risk 0.00cvss 4.9epss 0.01

    Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

  • CVE-2024-37165MedJul 30, 2024
    risk 0.00cvss 6.3epss 0.00

    Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy.…

  • CVE-2024-38360MedJul 15, 2024
    risk 0.00cvss 4.9epss 0.00

    Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed in stable version 3.2.3…

  • CVE-2024-37157MedJul 3, 2024
    risk 0.00cvss 6.4epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, a malicious actor could get the FastImage library to redirect requests to an internal Discourse IP. This issue is…

  • CVE-2024-36122LowJul 3, 2024
    risk 0.00cvss 2.4epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the Allow moderators to…

  • CVE-2024-36113MedJul 3, 2024
    risk 0.00cvss 4.9epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version 3.3.0.beta4-dev on the `tests-passed` branch, a rogue staff user could suspend other staff users preventing them from logging in…

  • CVE-2024-35234MedJul 3, 2024
    risk 0.00cvss 4.2epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, an attacker can execute arbitrary JavaScript on users’ browsers by posting a specific URL containing maliciously crafted meta…

  • CVE-2024-35227HigJul 3, 2024
    risk 0.00cvss 7.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully crafted malicious URL can reduce the availability of a Discourse instance. The problem has been…

  • CVE-2024-28242MedMar 15, 2024
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have backgrounds set. The issue is patched in the latest stable, beta and tests-passed version of Discourse. Users are advised to…

  • CVE-2024-27100MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting CSV files weren't enforcing limits on the sizes of the parameters that they accept. This could lead to excessive resource…

Page 10 of 15