Discourse
Source repositories
CVEs (285)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37633 | Hig | 0.00 | 7.4 | 0.01 | Aug 9, 2021 | Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched… | ||
| CVE-2021-32788 | Med | 0.00 | 4.3 | 0.01 | Jul 27, 2021 | Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff… | ||
| CVE-2019-15515 | Med | 0.00 | 6.5 | 0.01 | Aug 26, 2019 | Discourse 2.3.2 sends the CSRF token in the query string. | ||
| CVE-2019-1020018 | Hig | 0.00 | 7.3 | 0.01 | Jul 29, 2019 | Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link. | ||
| CVE-2019-1020017 | Med | 0.00 | 5.3 | 0.01 | Jul 29, 2019 | Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP. |
- risk 0.00cvss 7.4epss 0.01
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched…
- risk 0.00cvss 4.3epss 0.01
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff…
- risk 0.00cvss 6.5epss 0.01
Discourse 2.3.2 sends the CSRF token in the query string.
- risk 0.00cvss 7.3epss 0.01
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
- risk 0.00cvss 5.3epss 0.01
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
Page 15 of 15