Vulnerability index

Browse CVEs

207 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-23743 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permalinks pointing to access-restri… Discourse 3.5.4 / 2025.11.2+ Fix from $1,9502026-01-28 MEDIUM 6.5 CVE-2026-24742 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators can view sensit… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2026-21865 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-69218 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploa… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.4 CVE-2025-69289 Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 … Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-68666 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2025-68934 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit craft… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.4 CVE-2025-68933 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moder… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 CRITICAL 9.9 CVE-2025-68662 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in Final… Discourse 3.5.4 / 2025.11.2+ Fix from $2,3002026-01-28 MEDIUM 5.4 CVE-2025-68660 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated u… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2025-68479 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack pro… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2025-68659 Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of serv… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 6.1 CVE-2025-66488 Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 affects anyon… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.4 CVE-2025-67723 Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a content-security-policy-mitigated… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2025-64528 Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find… Discourse 3.5.3+ Fix from $1,6002025-12-30 MEDIUM 5.3 CVE-2025-61598 Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-… Discourse 3.5.2 / 3.6.0+ Fix from $1,6002025-10-28 MEDIUM 6.8 CVE-2025-59337 Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump an… Discourse 3.5.1 / 3.6.0+ Fix from $1,6002025-10-01 MEDIUM 5.4 CVE-2025-58054 Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of ch… Discourse 3.5.0 / 3.6.0+ Fix from $1,6002025-10-01 MEDIUM 5.4 CVE-2025-54411 Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect t… Discourse 3.5.0+ Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-53102 Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5.0.beta.8 on the `tests-passe… Discourse 3.4.6+ Fix from $2,3002025-07-29 HIGH 7.5 CVE-2025-49845 Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers_allowed_groups` site setting… Discourse 3.4.6+ Fix from $1,9502025-06-25 MEDIUM 6.1 CVE-2025-48954 Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security polic… Discourse 3.5.0+ Fix from $1,6002025-06-25 CRITICAL 9.8 CVE-2025-48877 Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version… Discourse 3.4.4 / 3.5.0+ Fix from $2,3002025-06-09 HIGH 7.5 CVE-2025-48053 Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version… Discourse 3.4.4 / 3.5.0+ Fix from $1,9502025-06-09 MEDIUM 6.1 CVE-2025-48062 Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version… Discourse 3.4.4 / 3.5.0+ Fix from $1,6002025-06-09 HIGH 7.5 CVE-2025-46813 Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d113… Discourse 3.5.0+ Fix from $1,9502025-05-05 MEDIUM 6.5 CVE-2024-53851 Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enfor… Discourse 3.3.3 / 3.4.0+ Fix from $1,6002025-02-04 MEDIUM 5.4 CVE-2024-53266 Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activit… Discourse 3.3.3 / 3.4.0+ Fix from $1,6002025-02-04 HIGH 8.2 CVE-2025-23023 Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request … Discourse 3.3.2+ Fix from $1,9502025-02-04 HIGH 8.2 CVE-2024-55948 Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR request to poison the anonymous… Discourse 3.3.2+ Fix from $1,9502025-02-04