Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Discourse

290 known vulnerabilities

6
CRITICAL
47
HIGH
203
MEDIUM
34
LOW

Top Products

discourse 263 calendar 4 discourse calendar 3 discourse-chat 3 discourse reactions 2 ai 1 microsoft authentication 1 group membership ip blocks 1 discourse jira 1 discourse-encrypt 1
290 CVEs · Page 5/6
5.4
CVE-2023-30538

Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacke

4.2
CVE-2023-29196

Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default inst

2.7
CVE-2023-28440

Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a

5.9
CVE-2023-28112

Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches,

5.7
CVE-2023-28111

Discourse is an open-source discussion platform. Prior to version 3.1.0.beta3 of the `beta` and `tests-passed` branches,

4.5
CVE-2023-28107

Discourse is an open-source discussion platform. Prior to version 3.0.2 of the `stable` branch and version 3.1.0.beta3 o

4.4
CVE-2023-25172

Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 o

6.5
CVE-2023-26040

Discourse is an open-source discussion platform. Between versions 3.1.0.beta2 and 3.1.0.beta3 of the `tests-passed` bran

4.3
CVE-2023-23622

Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 o

3.5
CVE-2023-23935

Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.be

3.1
CVE-2023-25169

discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a

5.3
CVE-2023-25819

Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. T

6.5
CVE-2023-25167

Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression de

5.3
CVE-2023-23615

Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any us

4.3
CVE-2023-23624

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 o

8.6
CVE-2023-23621

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 o

5.3
CVE-2023-23620

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b

3.5
CVE-2023-23616

Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b

4.3
CVE-2023-22740

Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are v

6.5
CVE-2023-22739

Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and

8.8
CVE-2023-22468

Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) an

6.8
CVE-2023-22455

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta

8.0
CVE-2023-22454

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta

5.3
CVE-2023-22453

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta

5.7
CVE-2022-46177

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta

5.7
CVE-2022-23549

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta

6.5
CVE-2022-23548

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta

5.5
CVE-2022-23546

In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's

3.5
CVE-2022-46168

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta

5.0
CVE-2022-46180

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create g

4.3
CVE-2022-46159

Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.be

8.8
CVE-2022-46162

discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rend

4.3
CVE-2022-46150

Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14

7.1
CVE-2022-46148

Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.b

3.5
CVE-2022-41944

Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr

3.5
CVE-2022-41921

Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim

4.3
CVE-2022-41913

Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar

6.5
CVE-2022-39385

Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a

5.3
CVE-2022-39378

Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on

8.9
CVE-2022-39356

Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single em

7.6
CVE-2022-39241

Discourse is a platform for community discussion. A malicious admin could use this vulnerability to perform port enumera

9.1
CVE-2022-39355

Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabl

4.3
CVE-2022-39279

discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some

5.4
CVE-2022-39270

DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in T

6.5
CVE-2022-39232

Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an

4.3
CVE-2022-39226

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be

7.2
CVE-2022-36068

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be

9.1
CVE-2022-36066

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be

5.4
CVE-2022-36057

Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse

7.2
CVE-2022-37458

Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.

Frequently Asked Questions

How many CVEs affect Discourse?

Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.

What are the most severe Discourse vulnerabilities?

Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Discourse vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Discourse Vulnerabilities

CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.

Get Started