Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2022-31095
discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an…
Discourse Chat
0.4+
MEDIUM 5.3
CVE-2022-31060
Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-pas…
Discourse
2.8.4+
MEDIUM 5.4
CVE-2022-31059
Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can…
Discourse Calendar
1.0.1+
MEDIUM 5.3
CVE-2022-31025
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-…
Discourse
2.8.4+
MEDIUM 5.3
CVE-2022-24824
Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged i…
Discourse
2.8.3+
MEDIUM 5.3
CVE-2022-24804
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo…
Discourse
2.8.3+
MEDIUM 6.5
CVE-2022-23641
Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2…
Discourse
2.8.1+
MEDIUM 5.3
CVE-2022-21677
Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group…
Discourse
after 2.7.12
HIGH 8.8
CVE-2022-21684
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` all…
Discourse
2.7.13+
MEDIUM 6.8
CVE-2021-43850
Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/mes…
Discourse
2.7.12+
MEDIUM 6.5
CVE-2021-43840
message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics feature…
Message Bus
3.3.7+
MEDIUM 5.3
CVE-2021-43794
Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such…
Discourse
2.7.11+
MEDIUM 5.3
CVE-2021-41271
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by in…
Discourse
after 2.7.9
HIGH 8.8
CVE-2021-41263
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails…
Rails Multisite
4.0.0+
CRITICAL 9.8
CVE-2021-41163EPSS 20%
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.…
Discourse
2.7.9+
MEDIUM 5.3
CVE-2021-41140
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given …
Discourse Reactions
0.2+
MEDIUM 6.1
CVE-2021-41095
Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` br…
Discourse
after 2.7.7
MEDIUM 5.3
CVE-2020-24327
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you ca…
Discourse
Patch available
HIGH 7.5
CVE-2021-41082
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user…
Discourse
2021-09-14+
MEDIUM 5.4
CVE-2021-39161
Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks.…
Discourse
2.7.8+
HIGH 7.5
CVE-2021-37693
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addre…
Discourse
2.7.8+
MEDIUM 6.1
CVE-2021-37633
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This v…
Discourse
2.7.8+
MEDIUM 5.4
CVE-2021-32764
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible …
Discourse
after 2.7.5
HIGH 7.5
CVE-2021-3138
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
Discourse
after 2.6.0
MEDIUM 6.5
CVE-2019-15515
Discourse 2.3.2 sends the CSRF token in the query string.
Discourse
Patch available
HIGH 7.3
CVE-2019-1020018
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
Discourse
2.3.0+
MEDIUM 5.3
CVE-2019-1020017
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
Discourse
2.3.0+