Discourse
290 known vulnerabilities
Top Products
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endp
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an app
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont
Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.
Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who know
Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response he
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp
Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug
Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable t
Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5
Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers
Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting wh
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the bet
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t
Discourse is an open source platform for community discussion. In affected versions users who disable chat in preference
Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline o
Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, a
Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a re
Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary Ja
Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br
Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th
Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi
Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affect
Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have loc
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the l
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attack
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then atte
Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rende
discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topi
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long t
Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could
Discourse is an open source platform for community discussion. In affected versions by creating replacement words with a
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on t
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o
Frequently Asked Questions
How many CVEs affect Discourse?
Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.
What are the most severe Discourse vulnerabilities?
Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Discourse vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Discourse Vulnerabilities
CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.
Get Started