VYPR

Vendor CVEs

Discourse (software)

All CVEs

308 total · sorted by risk
  • CVE-2026-31869MedMar 20, 2026
    risk 0.21cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the ComposerController#mentions endpoint reveals hidden group membership to any authenticated user who can message the group. By supplying allowed_names referencing a…

  • CVE-2026-33393MedMar 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allowed_spam_host_domains` check used `String#end_with?` without domain boundary validation, allowing domains like `attacker-example.com` to bypass spam protection…

  • CVE-2026-32099MedMar 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticated user could request a onebox…

  • CVE-2026-27491MedMar 19, 2026
    risk 0.21cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only moderation feature. The…

  • CVE-2024-31219MedApr 15, 2024
    risk 0.21cvss 4.3epss 0.00

    Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data are shown on the…

  • CVE-2026-27166MedMar 19, 2026
    risk 0.20cvss 4.1epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in…

  • CVE-2025-22601LowFeb 4, 2025
    risk 0.20cvss 3.1epss 0.00

    Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user to make changes to their own username via carefully crafted link using the `activate-account` route. This problem has been patched in the latest version of…

  • CVE-2023-32301LowJun 13, 2023
    risk 0.20cvss 3.1epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is patched in version 3.0.4 of…

  • CVE-2026-28227LowFeb 26, 2026
    risk 0.18cvss 2.7epss 0.03

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publish topics into staff-only categories via the `publish_to_category` topic timer, bypassing authorization checks. Versions 2025.12.2, 2026.1.1, and 2026.2.0…

  • CVE-2026-27153LowFeb 26, 2026
    risk 0.18cvss 2.7epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in `can_export_entity?`. The method allowed moderators to export…

  • CVE-2026-27151LowFeb 26, 2026
    risk 0.18cvss 2.7epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` action only checked `can_move_posts?` on the source topic but never validated write permissions on the destination topic. This allowed TL4 users and category…

  • CVE-2026-26979LowFeb 26, 2026
    risk 0.18cvss 2.7epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able to close, archive and pin topics in private categories they don't have access to. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known…

  • CVE-2023-28440LowApr 18, 2023
    risk 0.18cvss 2.7epss 0.01

    Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a Discourse administrator can lead to a long-running request and eventual timeout. This has the greatest potential impact in shared hosting environments where…

  • CVE-2026-33426LowMar 21, 2026
    risk 0.16cvss 3.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users with tag-editing permissions could edit and create synonyms for tags hidden in restricted tag groups, even if they lacked visibility into those tags. Versions…

  • CVE-2026-33422LowMar 20, 2026
    risk 0.16cvss 3.5epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_address` of a flagged user is exposed to any user who can access the review queue, including users who should not be able to see IP addresses. Versions…

  • CVE-2025-47288LowMay 29, 2025
    risk 0.16cvss 3.5epss 0.00

    Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there was a policy posted to a public topic that was tied to a private group then the group members could be shown to non-group members. This issue has been patched…

  • CVE-2024-56197LowFeb 4, 2025
    risk 0.14cvss 2.2epss 0.00

    Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when the "PM tags allowed for groups" option is enabled, the other user is a member of a group added to this option, and the PM has been tagged. This issue has been…

  • CVE-2024-52589LowDec 19, 2024
    risk 0.14cvss 2.2epss 0.00

    Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn the email of a user. This problem is patched in the latest version of Discourse. Users unable to upgrade should remove…

  • CVE-2025-46824LowMay 7, 2025
    risk 0.13cvss 3.1epss 0.00

    The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit eed3a80 of the…

  • CVE-2023-31142LowJun 13, 2023
    risk 0.13cvss 2.0epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has modified their general category permissions, they could be set back to the default. This issue is…

  • CVE-2026-33415LowMar 31, 2026
    risk 0.11cvss 2.7epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from…

  • CVE-2026-33394LowMar 19, 2026
    risk 0.11cvss 2.7epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure categories to moderators who…

  • CVE-2026-30888LowMar 20, 2026
    risk 0.07cvss 2.2epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy documents (ToS, guidelines, privacy policy) that they are explicitly prohibited from modifying. Versions 2026.3.0-latest.1,…

  • CVE-2026-33408LowMar 19, 2026
    risk 0.07cvss 2.2epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators were able to see the first 40 characters of post edits in PMs and private categories. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No…

  • CVE-2026-72729LowAug 10, 2026
    risk 0.06cvss epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in…

  • CVE-2021-41163CriOct 20, 2021
    risk 0.02cvss 10.0epss 0.20

    Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and…

  • CVE-2026-59828MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in…

  • CVE-2026-55424MedJul 9, 2026
    risk 0.00cvss 5.4epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured link to inject JavaScript…

  • CVE-2026-53963HigJul 9, 2026
    risk 0.00cvss 7.3epss 0.01

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator…

  • CVE-2026-53962MedJul 9, 2026
    risk 0.00cvss 5.4epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community…

  • CVE-2026-53961MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account…

  • CVE-2026-49256HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and unauthorized…

  • CVE-2026-46413MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2,…

  • CVE-2026-45788HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in…

  • CVE-2026-45780MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event…

  • CVE-2026-44787HigJul 9, 2026
    risk 0.00cvss 8.2epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with…

  • CVE-2026-55420HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and…

  • CVE-2025-64528MedDec 30, 2025
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0…

  • CVE-2025-61598MedOct 28, 2025
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to…

  • CVE-2025-59337MedOct 1, 2025
    risk 0.00cvss 6.8epss 0.00

    Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. In multisite setups, this allowed an admin of one site to access data or credentials from other sites.…

  • CVE-2025-58055MedOct 1, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to…

  • CVE-2025-58054LowOct 1, 2025
    risk 0.00cvss 3.5epss 0.00

    Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed…

  • CVE-2025-54411MedAug 19, 2025
    risk 0.00cvss 5.4epss 0.00

    Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.logged_in_members site…

  • CVE-2025-53102CriJul 29, 2025
    risk 0.00cvss 9.8epss 0.00

    Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passed` branch, upon issuing a physical security key for 2FA, the server generates a WebAuthn challenge, which the client signs. The…

  • CVE-2025-46813MedMay 5, 2025
    risk 0.00cvss 5.8epss 0.00

    Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some content on the site's…

  • CVE-2025-32376MedApr 30, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user from a site in it. This issue has been…

  • CVE-2025-24808MedMar 26, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. The requests might all go…

  • CVE-2024-53851MedFeb 4, 2025
    risk 0.00cvss 4.3epss 0.00

    Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enforcing limits on the number of URLs that it accepted, allowing a malicious user to inflict denial of service on some parts of the…

  • CVE-2024-45303MedSep 12, 2024
    risk 0.00cvss 6.1epss 0.00

    Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content…

  • CVE-2024-37299MedJul 30, 2024
    risk 0.00cvss 4.9epss 0.01

    Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5.

Page 4 of 7