Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Discourse

290 known vulnerabilities

6
CRITICAL
47
HIGH
203
MEDIUM
34
LOW

Top Products

discourse 263 calendar 4 discourse calendar 3 discourse-chat 3 discourse reactions 2 ai 1 microsoft authentication 1 group membership ip blocks 1 discourse jira 1 discourse-encrypt 1
290 CVEs · Page 6/6
6.5
CVE-2022-31184

Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen

5.3
CVE-2022-31182

Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static asset

5.7
CVE-2022-31096

Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an

4.3
CVE-2022-31095

discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se

5.3
CVE-2022-31060

Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5`

6.5
CVE-2022-31059

Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and

2.6
CVE-2022-31025

Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0be

4.3
CVE-2022-24866

Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve

5.3
CVE-2022-24850

Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by

5.3
CVE-2022-24824

Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for

5.3
CVE-2022-24804

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior

4.3
CVE-2022-24782

Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior

6.5
CVE-2022-23641

Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `

4.3
CVE-2022-21677

Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for t

4.3
CVE-2022-21684

Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0

4.3
CVE-2022-21678

Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8

4.3
CVE-2022-21642

Discourse is an open source platform for community discussion. In affected versions when composing a message from topic

6.8
CVE-2021-43850

Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of

4.4
CVE-2021-43840

message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message

4.3
CVE-2021-43827

discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote w

5.3
CVE-2021-43794

Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.

4.3
CVE-2021-43793

Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users

4.3
CVE-2021-43792

Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us

4.8
CVE-2021-41271

Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro

8.3
CVE-2021-41263

rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Ra

10.0
CVE-2021-41163

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l

5.3
CVE-2021-41140

Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affec

4.2
CVE-2021-41095

Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 a

5.3
CVE-2020-24327

Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing

7.5
CVE-2021-41082

Discourse is a platform for community discussion. In affected versions any private message that includes a group had its

4.4
CVE-2021-39161

Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross

4.3
CVE-2021-37703

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a use

5.3
CVE-2021-37693

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when

7.4
CVE-2021-37633

Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susce

4.3
CVE-2021-32788

Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre

8.1
CVE-2021-32764

Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube

7.5
CVE-2021-3138

In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

6.5
CVE-2019-15515

Discourse 2.3.2 sends the CSRF token in the query string.

7.3
CVE-2019-1020018

Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

5.3
CVE-2019-1020017

Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.

Frequently Asked Questions

How many CVEs affect Discourse?

Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.

What are the most severe Discourse vulnerabilities?

Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Discourse vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Discourse Vulnerabilities

CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.

Get Started