VYPR

Discourse

by Discourse (software)

Source repositories

CVEs (285)

  • CVE-2023-28112MedMar 17, 2023
    risk 0.00cvss 5.9epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, some user provided URLs were being passed to FastImage without SSRF protection. Insufficient protections could enable attackers to trigger outbound network…

  • CVE-2023-28111MedMar 17, 2023
    risk 0.00cvss 5.7epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, attackers are able to bypass Discourse's server-side request forgery (SSRF) protection for private IPv4 addresses by using a IPv4-mapped IPv6 address. The…

  • CVE-2023-28107MedMar 17, 2023
    risk 0.00cvss 4.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches, a user logged as an administrator can request backups multiple times, which will eat up all the connections to the…

  • CVE-2023-25172MedMar 17, 2023
    risk 0.00cvss 4.4epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-site scripting attacks on…

  • CVE-2023-26040MedMar 17, 2023
    risk 0.00cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue is patched in version…

  • CVE-2023-23622MedMar 17, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of whether the topic is in a read…

  • CVE-2023-23935LowMar 16, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all personal messages regardless of…

  • CVE-2023-25819MedMar 4, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `tests-passed` version of…

  • CVE-2023-25167MedFeb 8, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised…

  • CVE-2023-23624MedJan 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were using a specific hidden tag.…

  • CVE-2023-23621HigJan 28, 2023
    risk 0.00cvss 8.6epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, a malicious user can cause a regular expression denial of service using a carefully crafted user agent. This issue is…

  • CVE-2023-23620MedJan 28, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, the contents of latest/top routes for restricted tags can be accessed by unauthorized users. This issue is patched in version…

  • CVE-2023-23616LowJan 28, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could…

  • CVE-2023-22740MedJan 27, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of Resources Without Limits. Users can create chat drafts of an unlimited length, which can cause a denial of service by generating an…

  • CVE-2023-22455MedJan 5, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scripting attacks. This…

  • CVE-2023-22454HigJan 5, 2023
    risk 0.00cvss 8.0epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, pending post titles can be used for cross-site scripting attacks. Pending posts can be created by unprivileged…

  • CVE-2023-22453MedJan 5, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, the number of times a user posted in an arbitrary topic is exposed to unauthorized users through the…

  • CVE-2022-46177MedJan 5, 2023
    risk 0.00cvss 5.7epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, when a user requests for a password reset link email, then changes their primary email, the old reset email is…

  • CVE-2022-23549MedJan 5, 2023
    risk 0.00cvss 5.7epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, users can create posts with raw body longer than the `max_length` site setting by including html comments that…

  • CVE-2022-23548MedJan 5, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched…

Page 12 of 15