Vulnerability index

Browse CVEs

207 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Discourse MEDIUM 5.7
CVE-2023-25167

Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a caref…

Fix: 3.0.1+
Fix from $1,600 2023-02-08
Discourse MEDIUM 5.3
CVE-2023-23615

Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear titl…

Fix: after 3.0.0
Fix from $1,600 2023-02-03
Discourse HIGH 7.5
CVE-2023-23621

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passe…

Fix: 3.0.1+
Fix from $1,950 2023-01-28
Discourse MEDIUM 5.3
CVE-2023-23620

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `beta` and `tests-passed` branc…

Fix: 3.0.1+
Fix from $1,600 2023-01-28
Discourse MEDIUM 5.3
CVE-2023-23624

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passe…

Fix: 3.0.1+
Fix from $1,600 2023-01-28
Discourse MEDIUM 6.5
CVE-2023-22740

Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of R…

Fix: after 3.0.0
Fix from $1,600 2023-01-27
Discourse MEDIUM 6.5
CVE-2023-22739

Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) a…

Fix: 3.0.1+
Fix from $1,600 2023-01-26
Discourse MEDIUM 5.4
CVE-2023-22468

Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed),…

Fix: 2.8.13+
Fix from $1,600 2023-01-26
Discourse MEDIUM 6.1
CVE-2023-22455

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Discourse HIGH 8.1
CVE-2022-46177

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,950 2023-01-05
Discourse MEDIUM 6.1
CVE-2023-22454

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Discourse MEDIUM 5.3
CVE-2023-22453

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Discourse MEDIUM 6.5
CVE-2022-23548

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Discourse MEDIUM 6.5
CVE-2022-23549

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-p…

Fix: 2.8.14+
Fix from $1,600 2023-01-05
Discourse MEDIUM 5.5
CVE-2022-23546

In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, poss…

Fix: 2.9.0+
Fix from $1,600 2023-01-05
Mermaid MEDIUM 5.4
CVE-2022-46180

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid synta…

Fix: 1.1.0+
Fix from $1,600 2023-01-04
Discourse Bbcode CRITICAL 9.8
CVE-2022-46162

discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with …

Fix: 2022-11-30+
Fix from $2,300 2022-11-30
Discourse MEDIUM 5.4
CVE-2022-46148

Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta`…

Fix: after 2.8.10
Fix from $1,600 2022-11-29
Calendar MEDIUM 5.4
CVE-2022-41913

Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic.…

Patch available
Fix from $1,600 2022-11-14
Discourse MEDIUM 6.5
CVE-2022-39385

Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several privat…

Fix: 2.8.10+
Fix from $1,600 2022-11-14
Discourse HIGH 8.8
CVE-2022-39356

Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non…

Fix: 2.8.10+
Fix from $1,950 2022-11-02
Discourse MEDIUM 5.3
CVE-2022-39378

Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic …

Fix: 2.8.9+
Fix from $1,600 2022-11-02
Patreon CRITICAL 9.8
CVE-2022-39355

Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authenticatio…

Fix: 2022-10-26+
Fix from $2,300 2022-10-26
Discourse Chat MEDIUM 5.4
CVE-2022-39279

discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some places render a chat channel'…

Fix: 0.9+
Fix from $1,600 2022-10-06
Discotoc MEDIUM 5.4
CVE-2022-39270

DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in TOC-enabled categories (and ha…

Fix: 2.1.0+
Fix from $1,600 2022-10-06
Discourse HIGH 7.2
CVE-2022-36066

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests…

Fix: 2.8.9+
Fix from $1,950 2022-09-29
Discourse HIGH 7.2
CVE-2022-37458

Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.

Fix: after 2.8.7
Fix from $1,950 2022-09-02
Discourse HIGH 7.5
CVE-2022-31184

Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has…

Fix: after 2.8.6
Fix from $1,950 2022-08-01
Discourse MEDIUM 5.3
CVE-2022-31182

Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static assets could cause error responses…

Fix: 2.8.7+
Fix from $1,600 2022-08-01
Discourse MEDIUM 5.7
CVE-2022-31096

Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't ma…

Fix: after 2.8.4
Fix from $1,600 2022-06-27