Vulnerability index

Browse CVEs

207 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Discourse Chat MEDIUM 6.5
CVE-2022-31095

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an…

Fix: 0.4+
Fix from $1,600 2022-06-21
Discourse MEDIUM 5.3
CVE-2022-31060

Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-pas…

Fix: 2.8.4+
Fix from $1,600 2022-06-14
Discourse Calendar MEDIUM 5.4
CVE-2022-31059

Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can…

Fix: 1.0.1+
Fix from $1,600 2022-06-14
Discourse MEDIUM 5.3
CVE-2022-31025

Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-…

Fix: 2.8.4+
Fix from $1,600 2022-06-07
Discourse MEDIUM 5.3
CVE-2022-24824

Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged i…

Fix: 2.8.3+
Fix from $1,600 2022-04-14
Discourse MEDIUM 5.3
CVE-2022-24804

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo…

Fix: 2.8.3+
Fix from $1,600 2022-04-11
Discourse MEDIUM 6.5
CVE-2022-23641

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2…

Fix: 2.8.1+
Fix from $1,600 2022-02-15
Discourse MEDIUM 5.3
CVE-2022-21677

Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group…

Fix: after 2.7.12
Fix from $1,600 2022-01-14
Discourse HIGH 8.8
CVE-2022-21684

Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` all…

Fix: 2.7.13+
Fix from $1,950 2022-01-13
Discourse MEDIUM 6.8
CVE-2021-43850

Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/mes…

Fix: 2.7.12+
Fix from $1,600 2022-01-04
Message Bus MEDIUM 6.5
CVE-2021-43840

message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics feature…

Fix: 3.3.7+
Fix from $1,600 2021-12-17
Discourse MEDIUM 5.3
CVE-2021-43794

Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such…

Fix: 2.7.11+
Fix from $1,600 2021-12-01
Discourse MEDIUM 5.3
CVE-2021-41271

Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by in…

Fix: after 2.7.9
Fix from $1,600 2021-11-15
Rails Multisite HIGH 8.8
CVE-2021-41263

rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails…

Fix: 4.0.0+
Fix from $1,950 2021-11-15
Discourse CRITICAL 9.8
CVE-2021-41163EPSS 20%

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.…

Fix: 2.7.9+
Fix from $2,300 2021-10-20
Discourse Reactions MEDIUM 5.3
CVE-2021-41140

Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given …

Fix: 0.2+
Fix from $1,600 2021-10-19
Discourse MEDIUM 6.1
CVE-2021-41095

Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` br…

Fix: after 2.7.7
Fix from $1,600 2021-09-27
Discourse MEDIUM 5.3
CVE-2020-24327

Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you ca…

Patch available
Fix from $1,600 2021-09-23
Discourse HIGH 7.5
CVE-2021-41082

Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user…

Fix: 2021-09-14+
Fix from $1,950 2021-09-20
Discourse MEDIUM 5.4
CVE-2021-39161

Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks.…

Fix: 2.7.8+
Fix from $1,600 2021-08-26
Discourse HIGH 7.5
CVE-2021-37693

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addre…

Fix: 2.7.8+
Fix from $1,950 2021-08-13
Discourse MEDIUM 6.1
CVE-2021-37633

Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This v…

Fix: 2.7.8+
Fix from $1,600 2021-08-09
Discourse MEDIUM 5.4
CVE-2021-32764

Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible …

Fix: after 2.7.5
Fix from $1,600 2021-07-15
Discourse HIGH 7.5
CVE-2021-3138

In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

Fix: after 2.6.0
Fix from $1,950 2021-01-14
Discourse MEDIUM 6.5
CVE-2019-15515

Discourse 2.3.2 sends the CSRF token in the query string.

Patch available
Fix from $1,600 2019-08-26
Discourse HIGH 7.3
CVE-2019-1020018

Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

Fix: 2.3.0+
Fix from $1,950 2019-07-29
Discourse MEDIUM 5.3
CVE-2019-1020017

Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.

Fix: 2.3.0+
Fix from $1,600 2019-07-29