Vulnerability index

Browse CVEs

207 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Discourse MEDIUM 6.1
CVE-2024-56328

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by posting a malicious…

Fix: 3.3.3 / 3.4.0+
Fix from $1,600 2025-02-04
Discourse MEDIUM 6.1
CVE-2025-22602

Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary JavaScript on users' browsers b…

Fix: 3.3.4 / 3.4.0+
Fix from $1,600 2025-02-04
Discourse CRITICAL 9.1
CVE-2024-49765

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow…

Fix: 3.3.3 / 3.4.0+
Fix from $2,300 2024-12-19
Discourse MEDIUM 6.1
CVE-2024-52794

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched i…

Fix: 3.3.2 / 3.4.0+
Fix from $1,600 2024-12-19
Discourse MEDIUM 5.9
CVE-2024-53991EPSS 27%

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::Loca…

Fix: 3.3.2 / 3.4.0+
Fix from $1,600 2024-12-19
Discourse HIGH 8.2
CVE-2024-47773

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response …

Fix: 3.3.2+
Fix from $1,950 2024-10-08
Discourse MEDIUM 6.1
CVE-2024-47772

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a malicious…

Fix: 3.3.2 / 3.4.0+
Fix from $1,600 2024-10-07
Discourse HIGH 8.2
CVE-2024-45051

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based res…

Fix: 3.3.2 / 3.4.0+
Fix from $1,950 2024-10-07
Calendar MEDIUM 6.1
CVE-2024-45303

Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susce…

Fix: 0.5+
Fix from $1,600 2024-09-12
Discourse MEDIUM 6.1
CVE-2024-39320

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any doma…

Fix: 3.2.5+
Fix from $1,600 2024-07-30
Discourse HIGH 7.5
CVE-2024-37299

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the…

Fix: 3.2.5+
Fix from $1,950 2024-07-30
Discourse MEDIUM 6.1
CVE-2024-37165

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability …

Fix: 3.2.3+
Fix from $1,600 2024-07-30
Discourse MEDIUM 5.3
CVE-2024-37157

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passe…

Fix: 3.2.3 / 3.3.0+
Fix from $1,600 2024-07-03
Discourse MEDIUM 6.5
CVE-2024-36113

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on the `beta` branch, and version…

Fix: 3.2.3 / 3.3.0+
Fix from $1,600 2024-07-03
Discourse MEDIUM 6.1
CVE-2024-35234

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, …

Fix: 3.2.3 / 3.3.0+
Fix from $1,600 2024-07-03
Discourse HIGH 7.5
CVE-2024-35227

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, …

Fix: after 3.2.2
Fix from $1,950 2024-07-03
Discourse HIGH 7.5
CVE-2024-28242

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret categories exist when they have…

Fix: 3.2.0 / 3.3.0+
Fix from $1,950 2024-03-15
Discourse MEDIUM 6.5
CVE-2024-27085

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily la…

Fix: 3.2.0 / 3.3.0+
Fix from $1,600 2024-03-15
Discourse MEDIUM 6.5
CVE-2024-27100

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting…

Fix: 3.2.1 / 3.3.0+
Fix from $1,600 2024-03-15
Discourse HIGH 7.5
CVE-2024-24827

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker…

Fix: 3.2.0 / 3.3.0+
Fix from $1,950 2024-03-15
Discourse MEDIUM 5.3
CVE-2024-24748

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret subcategory exists under a pu…

Fix: after 3.2.0
Fix from $1,600 2024-03-15
Calendar MEDIUM 5.3
CVE-2024-24817

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior…

Fix: 0.4+
Fix from $1,600 2024-02-22
Ai HIGH 7.2
CVE-2024-23654

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactio…

Fix: 2024-02-21+
Fix from $1,950 2024-02-21
Microsoft Authentication HIGH 8.1
CVE-2023-46241

`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an att…

Fix: 2024-02-20+
Fix from $1,950 2024-02-21
Group Membership Ip Blocks MEDIUM 5.3
CVE-2024-24755

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-mem…

Patch available
Fix from $1,600 2024-02-01
Discourse MEDIUM 6.1
CVE-2024-23834

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerab…

Fix: 3.1.5 / 3.2.0+
Fix from $1,600 2024-01-30
Discourse HIGH 7.5
CVE-2023-48297

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead…

Fix: 3.1.4+
Fix from $1,950 2024-01-12
Discourse CRITICAL 9.8
CVE-2023-47121

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an…

Fix: 3.1.3 / 3.2.0+
Fix from $2,300 2023-11-10
Discourse HIGH 7.5
CVE-2023-47120

Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 throug…

Fix: 3.1.3+
Fix from $1,950 2023-11-10
Discourse MEDIUM 6.1
CVE-2023-47119

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an…

Fix: 3.1.3 / 3.2.0+
Fix from $1,600 2023-11-10