Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Discourse

290 known vulnerabilities

6
CRITICAL
47
HIGH
203
MEDIUM
34
LOW

Top Products

discourse 263 calendar 4 discourse calendar 3 discourse-chat 3 discourse reactions 2 ai 1 microsoft authentication 1 group membership ip blocks 1 discourse jira 1 discourse-encrypt 1
290 CVEs · Page 3/6
7.6
CVE-2025-68662

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn

5.4
CVE-2025-68660

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endp

4.3
CVE-2025-68659

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an app

7.1
CVE-2025-68479

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su

4.6
CVE-2025-67723

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont

4.6
CVE-2025-66488

Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.

5.3
CVE-2025-64528

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who know

5.3
CVE-2025-61598

Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response he

6.8
CVE-2025-59337

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be

4.3
CVE-2025-58055

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp

3.5
CVE-2025-58054

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug

5.4
CVE-2025-54411

Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable t

9.8
CVE-2025-53102

Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5

7.5
CVE-2025-49845

Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers

8.1
CVE-2025-48954

Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting wh

9.8
CVE-2025-48877

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t

7.1
CVE-2025-48062

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t

7.5
CVE-2025-48053

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of t

5.8
CVE-2025-46813

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd

4.3
CVE-2025-32376

Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the bet

4.3
CVE-2025-24972

Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t

4.3
CVE-2025-24808

Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on t

4.3
CVE-2024-53994

Discourse is an open source platform for community discussion. In affected versions users who disable chat in preference

4.3
CVE-2024-53851

Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline o

4.3
CVE-2024-53266

Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, a

8.2
CVE-2025-23023

Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a re

6.5
CVE-2025-22602

Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary Ja

3.1
CVE-2025-22601

Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user

6.5
CVE-2024-56328

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br

2.2
CVE-2024-56197

Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th

8.2
CVE-2024-55948

Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re

7.5
CVE-2024-53991

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi

6.8
CVE-2024-52794

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affect

2.2
CVE-2024-52589

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin

5.3
CVE-2024-49765

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have loc

8.2
CVE-2024-47773

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache

6.5
CVE-2024-47772

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br

5.3
CVE-2024-45297

Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the l

8.2
CVE-2024-45051

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attack

7.5
CVE-2024-43789

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then atte

6.1
CVE-2024-45303

Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rende

4.3
CVE-2024-21658

discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topi

6.1
CVE-2024-39320

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to

4.9
CVE-2024-37299

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long t

6.3
CVE-2024-37165

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could

4.9
CVE-2024-38360

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with a

6.4
CVE-2024-37157

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o

2.4
CVE-2024-36122

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o

4.9
CVE-2024-36113

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on t

4.2
CVE-2024-35234

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o

Frequently Asked Questions

How many CVEs affect Discourse?

Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.

What are the most severe Discourse vulnerabilities?

Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Discourse vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Discourse Vulnerabilities

CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.

Get Started