VYPR

Vendor CVEs

Discourse (software)

All CVEs

308 total · sorted by risk
  • CVE-2025-48877CriJun 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in the default `allowed_iframes` site setting, and it can…

  • CVE-2023-22468HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry out cross-site scripting…

  • CVE-2024-47773HigOct 8, 2024
    risk 0.56cvss 8.2epss 0.02

    Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest…

  • CVE-2023-48297HigJan 12, 2024
    risk 0.56cvss 8.6epss 0.01

    Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to a very long array of users. This issue was patched in versions 3.1.4 and beta 3.2.0.beta5.

  • CVE-2025-48954HigJun 25, 2025
    risk 0.53cvss 8.1epss 0.01

    Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue. As a workaround, have the content security policy…

  • CVE-2025-23023HigFeb 4, 2025
    risk 0.53cvss 8.2epss 0.00

    Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This issue only…

  • CVE-2024-55948HigFeb 4, 2025
    risk 0.53cvss 8.2epss 0.00

    Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous cache (for example, the cache may have a response with missing preloaded data). This issue only affects anonymous visitors of…

  • CVE-2024-45051HigOct 7, 2024
    risk 0.53cvss 8.2epss 0.00

    Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and…

  • CVE-2021-32764HigJul 15, 2021
    risk 0.53cvss 8.1epss 0.01

    Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy.…

  • CVE-2024-54142CriJan 14, 2025
    risk 0.52cvss 9.0epss 0.00

    Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversation had HTML entities those could leak into the Discourse application when a user visited a post with a onebox to said conversation.…

  • CVE-2023-45131HigOct 16, 2023
    risk 0.52cvss 7.5epss 0.02

    Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known…

  • CVE-2023-43659HigOct 16, 2023
    risk 0.52cvss 8.0epss 0.00

    Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in the 3.1.1 stable release as…

  • CVE-2024-53991HigDec 19, 2024
    risk 0.51cvss 7.5epss 0.27

    Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of the Discourse backup file,…

  • CVE-2026-72730HigAug 10, 2026
    risk 0.50cvss 8.7epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and…

  • CVE-2026-26265HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items endpoint allows any user, including anonymous users, to retrieve private user field values for all users in the directory. The…

  • CVE-2026-26078HigFeb 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty string as the key. Since the…

  • CVE-2026-23743HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restricted resources (private topics, categories, posts, or hidden tags) were redirecting users to URLs containing the resource slug,…

  • CVE-2025-68662HigJan 28, 2026
    risk 0.49cvss 7.6epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in versions 3.5.4, 2025.11.2,…

  • CVE-2025-49845HigJun 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting. Only users that belong to groups specified in the site setting are allowed to view posts typed `whisper`. However, it has been…

  • CVE-2025-48053HigJun 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, sending a malicious URL in a PM to a bot user can cause a reduced the availability…

  • CVE-2024-43789HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability of a Discourse instance. This problem has been patched in the latest version of…

  • CVE-2023-44388HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse.…

  • CVE-2022-39241HigNov 2, 2022
    risk 0.49cvss 7.6epss 0.01

    Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumeration on the local host or other hosts on the internal network, as well as against hosts on the Internet. Latest `stable`, `beta`, and `test-passed` versions…

  • CVE-2021-3138HigJan 14, 2021
    risk 0.49cvss 7.5epss 0.03

    In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

  • CVE-2022-37458HigSep 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.

  • CVE-2021-41263HigNov 15, 2021
    risk 0.47cvss 8.3epss 0.01

    rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be…

  • CVE-2025-68479HigJan 28, 2026
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack proper checking for ownership before making changes. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No…

  • CVE-2025-48062HigJun 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, certain invites via email may result in HTML injection in the email body if the…

  • CVE-2022-46148HigNov 29, 2022
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability…

  • CVE-2025-68933MedJan 28, 2026
    risk 0.45cvss 6.9epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and restricted categories they…

  • CVE-2024-52794MedDec 19, 2024
    risk 0.44cvss 6.8epss 0.00

    Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

  • CVE-2023-36473MedJul 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack…

  • CVE-2026-44786HigJun 12, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public category channels are published to MessageBus without permission scoping, so any…

  • CVE-2026-33427HigMar 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a legitimate Discourse authorization page to display an attacker-controlled domain, facilitating social engineering attacks against…

  • CVE-2026-29072HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right conditions. Versions…

  • CVE-2026-27934HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized users, leading to information…

  • CVE-2026-27149MedFeb 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in PM tag filtering (`list_private_messages_tag`) allows bypassing tag filter conditions, potentially disclosing unauthorized private message metadata. Versions…

  • CVE-2026-26077MedFeb 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentication token when no token was…

  • CVE-2026-24742MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensitive information in staff action logs that should be restricted to administrators only. The exposed information includes webhook…

  • CVE-2026-21865MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal messages to public topics when they shouldn't have access. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and…

  • CVE-2025-69218MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all uploaded files on the site,…

  • CVE-2025-68934MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60 seconds per request. This…

  • CVE-2025-68666MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users with moderation privileges even though moderators should not have access to the archives. Private topic/post content made by the…

  • CVE-2025-22602MedFeb 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary JavaScript on users' browsers by posting a malicious video placeholder html element. This issue only affects sites with CSP disabled. This problem has been…

  • CVE-2024-56328MedFeb 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by posting a maliciously crafted onebox url. This issue only affects sites with CSP disabled. This problem has been patched in the latest version of…

  • CVE-2024-47772MedOct 7, 2024
    risk 0.42cvss 6.5epss 0.00

    Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it. This issue only affects sites with CSP disabled. This problem is patched in the latest…

  • CVE-2023-41043MedSep 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious admin could create extremely large icons sprites, which would then be cached in each server process. This…

  • CVE-2023-40588MedSep 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user could add a 2FA or security key with a carefully crafted name to their account and cause a denial of…

  • CVE-2023-38706MedSep 15, 2023
    risk 0.42cvss 6.5epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passed` branches, a malicious user can create an unlimited number of drafts with very long draft keys which may end up exhausting the…

  • CVE-2023-22739MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) are subject to Allocation of Resources Without Limits or Throttling. As there is no limit on data contained in a draft, a malicious…

Page 1 of 7