VYPR

Discourse

by Discourse (software)

Source repositories

CVEs (285)

  • CVE-2023-44388HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse.…

  • CVE-2022-39241HigNov 2, 2022
    risk 0.49cvss 7.6epss 0.01

    Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, and `test-passed` versions…

  • CVE-2021-3138HigJan 14, 2021
    risk 0.49cvss 7.5epss 0.03

    In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

  • CVE-2022-37458HigSep 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.

  • CVE-2025-68479HigJan 28, 2026
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No…

  • CVE-2025-48062HigJun 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, certain invites via email may result in HTML injection in the email body if the…

  • CVE-2022-46148HigNov 29, 2022
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability…

  • CVE-2025-68933MedJan 28, 2026
    risk 0.45cvss 6.9epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and restricted categories they…

  • CVE-2024-52794MedDec 19, 2024
    risk 0.44cvss 6.8epss 0.00

    Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

  • CVE-2023-36473MedJul 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack…

  • CVE-2026-44786HigJun 12, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public category channels are published to MessageBus without permission scoping, so any…

  • CVE-2026-33427HigMar 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a legitimate Discourse authorization page to display an attacker-controlled domain, facilitating social engineering attacks against…

  • CVE-2026-29072HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right conditions. Versions…

  • CVE-2026-27934HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized users, leading to information…

  • CVE-2026-27149MedFeb 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in PM tag filtering (`list_private_messages_tag`) allows bypassing tag filter conditions, potentially disclosing unauthorized private message metadata. Versions…

  • CVE-2026-26077MedFeb 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentication token when no token was…

  • CVE-2026-24742MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensitive information in staff action logs that should be restricted to administrators only. The exposed information includes webhook…

  • CVE-2026-21865MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and…

  • CVE-2025-69218MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all uploaded files on the site,…

  • CVE-2025-68934MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60 seconds per request. This…

Page 2 of 15