VYPR

Vendor CVEs

Discourse (software)

All CVEs

308 total · sorted by risk
  • CVE-2021-41082HigSep 20, 2021
    risk 0.00cvss 7.5epss 0.02

    Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not…

  • CVE-2021-37703MedAug 13, 2021
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a user's read state for a topic such as the last read post number and the notification level is exposed.

  • CVE-2021-37693MedAug 13, 2021
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting…

  • CVE-2021-37633HigAug 9, 2021
    risk 0.00cvss 7.4epss 0.01

    Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched…

  • CVE-2021-32788MedJul 27, 2021
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff…

  • CVE-2019-15515MedAug 26, 2019
    risk 0.00cvss 6.5epss 0.01

    Discourse 2.3.2 sends the CSRF token in the query string.

  • CVE-2019-1020018HigJul 29, 2019
    risk 0.00cvss 7.3epss 0.01

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

  • CVE-2019-1020017MedJul 29, 2019
    risk 0.00cvss 5.3epss 0.01

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.

Page 7 of 7