VYPR

Discourse

by Discourse (software)

Source repositories

CVEs (290)

  • CVE-2023-38498MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite…

  • CVE-2023-37906MedJul 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edit reason. The issue is…

  • CVE-2023-37904LowJul 28, 2023
    risk 0.00cvss 2.6epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in version 3.0.6 of the `stable`…

  • CVE-2023-37467MedJul 28, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous…

  • CVE-2023-36818MedJul 14, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this…

  • CVE-2023-28112MedMar 17, 2023
    risk 0.00cvss 5.9epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, some user provided URLs were being passed to FastImage without SSRF protection. Insufficient protections could enable attackers to trigger outbound network…

  • CVE-2023-28111MedMar 17, 2023
    risk 0.00cvss 5.7epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches, attackers are able to bypass Discourse's server-side request forgery (SSRF) protection for private IPv4 addresses by using a IPv4-mapped IPv6 address. The…

  • CVE-2023-28107MedMar 17, 2023
    risk 0.00cvss 4.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 of the `beta` and `tests-passed` branches, a user logged as an administrator can request backups multiple times, which will eat up all the connections to the…

  • CVE-2023-25172MedMar 17, 2023
    risk 0.00cvss 4.4epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-site scripting attacks on…

  • CVE-2023-26040MedMar 17, 2023
    risk 0.00cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` branch, editing or responding to a chat message containing malicious content could lead to a cross-site scripting attack. This issue is patched in version…

  • CVE-2023-23622MedMar 17, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, the count of topics displayed for a tag is a count of all regular topics regardless of whether the topic is in a read…

  • CVE-2023-23935LowMar 16, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all personal messages regardless of…

  • CVE-2023-25819MedMar 4, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `tests-passed` version of…

  • CVE-2023-25167MedFeb 8, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised…

  • CVE-2023-23624MedJan 28, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, someone can use the `exclude_tag param` to filter out topics and deduce which ones were using a specific hidden tag.…

  • CVE-2023-23621HigJan 28, 2023
    risk 0.00cvss 8.6epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, a malicious user can cause a regular expression denial of service using a carefully crafted user agent. This issue is…

  • CVE-2023-23620MedJan 28, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, the contents of latest/top routes for restricted tags can be accessed by unauthorized users. This issue is patched in version…

  • CVE-2023-23616LowJan 28, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branches, when submitting a membership request, there is no character limit for the reason provided with the request. This could…

  • CVE-2023-22740MedJan 27, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of Resources Without Limits. Users can create chat drafts of an unlimited length, which can cause a denial of service by generating an…

  • CVE-2023-22455MedJan 5, 2023
    risk 0.00cvss 6.8epss 0.00

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-passed` branches, tag descriptions, which can be updated by moderators, can be used for cross-site scripting attacks. This…

Page 12 of 15