VYPR

Vendor CVEs

Discourse (software)

All CVEs

313 total · sorted by risk
  • CVE-2021-43792MedDec 1, 2021
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who use the "Tags are visible only to the following groups" feature. A tag group may only allow a certain group (e.g. staff) to view certain tags. Users who were…

  • CVE-2021-41271MedNov 15, 2021
    risk 0.00cvss 4.8epss 0.01

    Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by intermediate proxies. This could cause a loss of confidentiality for some content. This issue is patched in the latest stable, beta…

  • CVE-2021-41140MedOct 19, 2021
    risk 0.00cvss 5.3epss 0.01

    Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in version 0.2 of discourse-reaction. Users who…

  • CVE-2021-41095MedSep 27, 2021
    risk 0.00cvss 4.2epss 0.01

    Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` branch, versions 2.8.0.beta6 and earlier of the `beta` branch, and versions 2.8.0.beta6 and earlier of the `tests-passed` branch.…

  • CVE-2020-24327MedSep 23, 2021
    risk 0.00cvss 5.3epss 0.01

    Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.

  • CVE-2021-41082HigSep 20, 2021
    risk 0.00cvss 7.5epss 0.02

    Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not…

  • CVE-2021-37703MedAug 13, 2021
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a user's read state for a topic such as the last read post number and the notification level is exposed.

  • CVE-2021-37693MedAug 13, 2021
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting…

  • CVE-2021-37633HigAug 9, 2021
    risk 0.00cvss 7.4epss 0.01

    Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched…

  • CVE-2021-32788MedJul 27, 2021
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff…

  • CVE-2019-15515MedAug 26, 2019
    risk 0.00cvss 6.5epss 0.01

    Discourse 2.3.2 sends the CSRF token in the query string.

  • CVE-2019-1020018HigJul 29, 2019
    risk 0.00cvss 7.3epss 0.01

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

  • CVE-2019-1020017MedJul 29, 2019
    risk 0.00cvss 5.3epss 0.01

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.

Page 7 of 7