VYPR

Discourse

by Discourse (software)

Source repositories

CVEs (285)

  • CVE-2024-27085MedMar 15, 2024
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily large data in parameters used in the invite route. The problem has been patched in the latest version of Discourse. Users are…

  • CVE-2024-24827MedMar 15, 2024
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker to carry out a DoS attack on the server since creating an upload can be a resource intensive process. Do note that the impact…

  • CVE-2024-24748MedMar 15, 2024
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a public category which has no public subcategories. The issue is patched in the latest stable, beta and tests-passed version of…

  • CVE-2024-23834MedJan 30, 2024
    risk 0.00cvss 6.3epss 0.00

    Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. The vulnerability is patched in…

  • CVE-2023-49099LowJan 12, 2024
    risk 0.00cvss 3.1epss 0.00

    Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 and 3.1.4.

  • CVE-2023-47121LowNov 10, 2023
    risk 0.00cvss 3.4epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request forgery. The issue is patched in version…

  • CVE-2023-47120HigNov 10, 2023
    risk 0.00cvss 7.5epss 0.01

    Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 through 3.2.0.beta2 of the `beta` and `tests-passed` branches, Redis memory can be depleted by crafting a site with an abnormally long…

  • CVE-2023-47119MedNov 10, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through our Onebox engine. The issue is patched…

  • CVE-2023-46130MedNov 10, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some theme components allow users to add svgs with unlimited `height` attributes, and this can affect…

  • CVE-2023-45816LowNov 10, 2023
    risk 0.00cvss 3.3epss 0.00

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark reminder is sent and an unread notification is generated, but…

  • CVE-2023-45806MedNov 10, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that…

  • CVE-2023-44384MedOct 6, 2023
    risk 0.00cvss 4.1epss 0.00

    Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site…

  • CVE-2023-43657HigSep 28, 2023
    risk 0.00cvss 7.2epss 0.00

    discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a…

  • CVE-2023-38685MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized users. The issue is patched in…

  • CVE-2023-38684MedJul 28, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple controller actions, Discourse accepts limit params but does not impose any upper bound on the values…

  • CVE-2023-38498MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite…

  • CVE-2023-37906MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edit reason. The issue is…

  • CVE-2023-37904LowJul 28, 2023
    risk 0.00cvss 2.6epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in version 3.0.6 of the `stable`…

  • CVE-2023-37467MedJul 28, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous…

  • CVE-2023-36818MedJul 14, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this…

Page 11 of 15