Discourse
290 known vulnerabilities
Top Products
Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacke
Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default inst
Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a
Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches,
Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches,
Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 o
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 o
Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` bran
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 o
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.be
discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a
Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. T
Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression de
Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any us
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 o
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 o
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b
Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are v
Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and
Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) an
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta
In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta
Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create g
Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.be
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rend
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14
Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.b
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim
Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a
Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single em
Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumera
Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabl
discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some
DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in T
Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse
Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
Frequently Asked Questions
How many CVEs affect Discourse?
Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.
What are the most severe Discourse vulnerabilities?
Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Discourse vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Discourse Vulnerabilities
CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.
Get Started