Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Discourse

290 known vulnerabilities

6
CRITICAL
47
HIGH
203
MEDIUM
34
LOW

Top Products

discourse 263 calendar 4 discourse calendar 3 discourse-chat 3 discourse reactions 2 ai 1 microsoft authentication 1 group membership ip blocks 1 discourse jira 1 discourse-encrypt 1
290 CVEs · Page 4/6
7.5
CVE-2024-35227

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o

5.3
CVE-2024-28242

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret ca

6.5
CVE-2024-27100

Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users,

6.5
CVE-2024-27085

Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite oth

5.3
CVE-2024-24827

Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it ma

5.3
CVE-2024-24748

Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret

4.3
CVE-2024-24817

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discuss

4.1
CVE-2024-23654

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c393

6.5
CVE-2024-26145

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited us

9.0
CVE-2023-46241

`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft

4.3
CVE-2024-24755

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP

6.3
CVE-2024-23834

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in s

4.3
CVE-2024-21655

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed.

3.1
CVE-2023-49099

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with

3.5
CVE-2023-49098

Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifi

8.6
CVE-2023-48297

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@

3.4
CVE-2023-47121

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

7.5
CVE-2023-47120

Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch an

5.3
CVE-2023-47119

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

4.3
CVE-2023-46130

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

3.3
CVE-2023-45816

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

4.3
CVE-2023-45806

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

7.5
CVE-2023-45131

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticate

5.3
CVE-2023-44391

Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even wh

7.5
CVE-2023-44388

Discourse is an open source platform for community discussion. A malicious request can cause production log files to qui

3.7
CVE-2023-43814

Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can

8.0
CVE-2023-43659

Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Sc

8.0
CVE-2023-43658

dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar i

4.9
CVE-2023-45147

Discourse is an open source community platform. In affected versions any user can create a topic and add arbitrary custo

4.1
CVE-2023-44384

Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automati

7.2
CVE-2023-43657

discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encry

6.5
CVE-2023-41043

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o

4.9
CVE-2023-41042

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o

6.5
CVE-2023-40588

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o

6.5
CVE-2023-38706

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 o

4.3
CVE-2023-38685

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o

5.3
CVE-2023-38684

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o

4.3
CVE-2023-38498

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o

4.3
CVE-2023-37906

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o

2.6
CVE-2023-37904

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o

6.8
CVE-2023-37467

Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches,

6.5
CVE-2023-36818

Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar secti

3.5
CVE-2023-36466

Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to b

6.8
CVE-2023-36473

Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow X

4.8
CVE-2023-34250

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o

3.1
CVE-2023-32301

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o

5.4
CVE-2023-32061

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o

2.0
CVE-2023-31142

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o

4.3
CVE-2023-30611

Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform.

4.2
CVE-2023-30606

Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator ca

Frequently Asked Questions

How many CVEs affect Discourse?

Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.

What are the most severe Discourse vulnerabilities?

Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Discourse vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Discourse Vulnerabilities

CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.

Get Started