Vulnerability index

Browse CVEs

207 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-31095 discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an… Discourse Chat 0.4+ Fix from $1,6002022-06-21 MEDIUM 5.3 CVE-2022-31060 Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5` in the `beta` and `tests-pas… Discourse 2.8.4+ Fix from $1,6002022-06-14 MEDIUM 5.4 CVE-2022-31059 Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can… Discourse Calendar 1.0.1+ Fix from $1,6002022-06-14 MEDIUM 5.3 CVE-2022-31025 Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0beta5 on the `beta` and `tests-… Discourse 2.8.4+ Fix from $1,6002022-06-07 MEDIUM 5.3 CVE-2022-24824 Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for anonymous (i.e. not logged i… Discourse 2.8.3+ Fix from $1,6002022-04-14 MEDIUM 5.3 CVE-2022-24804 Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo… Discourse 2.8.3+ Fix from $1,6002022-04-11 MEDIUM 6.5 CVE-2022-23641 Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `beta` branch, and 2.9.0.beta2… Discourse 2.8.1+ Fix from $1,6002022-02-15 MEDIUM 5.3 CVE-2022-21677 Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for the group as well as the group… Discourse after 2.7.12 Fix from $1,6002022-01-14 HIGH 8.8 CVE-2022-21684 Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` all… Discourse 2.7.13+ Fix from $1,9502022-01-13 MEDIUM 6.8 CVE-2021-43850 Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of Service attack via the `/mes… Discourse 2.7.12+ Fix from $1,6002022-01-04 MEDIUM 6.5 CVE-2021-43840 message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics feature… Message Bus 3.3.7+ Fix from $1,6002021-12-17 MEDIUM 5.3 CVE-2021-43794 Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such… Discourse 2.7.11+ Fix from $1,6002021-12-01 MEDIUM 5.3 CVE-2021-41271 Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by in… Discourse after 2.7.9 Fix from $1,6002021-11-15 HIGH 8.8 CVE-2021-41263 rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails… Rails Multisite 4.0.0+ Fix from $1,9502021-11-15 CRITICAL 9.8 CVE-2021-41163EPSS 20% Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution.… Discourse 2.7.9+ Fix from $2,3002021-10-20 MEDIUM 5.3 CVE-2021-41140 Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given … Discourse Reactions 0.2+ Fix from $1,6002021-10-19 MEDIUM 6.1 CVE-2021-41095 Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 and earlier of the `stable` br… Discourse after 2.7.7 Fix from $1,6002021-09-27 MEDIUM 5.3 CVE-2020-24327 Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you ca… Discourse Patch available Fix from $1,6002021-09-23 HIGH 7.5 CVE-2021-41082 Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user… Discourse 2021-09-14+ Fix from $1,9502021-09-20 MEDIUM 5.4 CVE-2021-39161 Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks.… Discourse 2.7.8+ Fix from $1,6002021-08-26 HIGH 7.5 CVE-2021-37693 Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addre… Discourse 2.7.8+ Fix from $1,9502021-08-13 MEDIUM 6.1 CVE-2021-37633 Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This v… Discourse 2.7.8+ Fix from $1,6002021-08-09 MEDIUM 5.4 CVE-2021-32764 Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible … Discourse after 2.7.5 Fix from $1,6002021-07-15 HIGH 7.5 CVE-2021-3138 In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms. Discourse after 2.6.0 Fix from $1,9502021-01-14 MEDIUM 6.5 CVE-2019-15515 Discourse 2.3.2 sends the CSRF token in the query string. Discourse Patch available Fix from $1,6002019-08-26 HIGH 7.3 CVE-2019-1020018 Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link. Discourse 2.3.0+ Fix from $1,9502019-07-29 MEDIUM 5.3 CVE-2019-1020017 Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP. Discourse 2.3.0+ Fix from $1,6002019-07-29