Discourse
290 known vulnerabilities
Top Products
Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen
Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static asset
Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an
discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se
Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5`
Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and
Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0be
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve
Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by
Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior
Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior
Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `
Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for t
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8
Discourse is an open source platform for community discussion. In affected versions when composing a message from topic
Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of
message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message
discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote w
Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.
Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users
Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Ra
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affec
Discourse is an open source discussion platform. There is a cross-site scripting (XSS) vulnerability in versions 2.7.7 a
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its
Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a use
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susce
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
Discourse 2.3.2 sends the CSRF token in the query string.
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
Frequently Asked Questions
How many CVEs affect Discourse?
Discourse has 290 CVE records in our database, including 6 critical and 47 high severity vulnerabilities.
What are the most severe Discourse vulnerabilities?
Discourse has 6 critical severity (CVSS 9.0+) and 47 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Discourse vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Discourse products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Discourse Vulnerabilities
CyberStrike scans your infrastructure for Discourse vulnerabilities and provides real-time remediation guidance.
Get Started