Discourse
290 known vulnerabilities
Top Products
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret ca
Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users,
Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite oth
Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it ma
Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discuss
discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c393
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us
`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft
discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP
Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in s
Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed.
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifi
Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch an
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticate
Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even wh
Discourse is an open source platform for community discussion. A malicious request can cause production log files to qui
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can
Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Sc
dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar i
Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custo
Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati
discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encry
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches,
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar secti
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to b
Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow X
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform.
Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator ca
Frequently Asked Questions
How many CVEs affect Discourse?
Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.
What are the most severe Discourse vulnerabilities?
Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Discourse vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Discourse Vulnerabilities
CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.
Get Started