Loading HuntDB...

Discourse

21 Products 157 CVEs

CVE Severity Distribution (All Time)

Critical
5
High
24
Medium
109
Low
19

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 11 CVEs

Recent CVEs

View all
CVE-2024-54142 CRITICAL 7 months, 3 weeks ago

Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations into posts, if the conversatio…

CVE-2024-49765 MEDIUM 8 months, 3 weeks ago

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow…

CVE-2024-52589 LOW 8 months, 3 weeks ago

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that c…

CVE-2024-52794 MEDIUM 8 months, 3 weeks ago

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched i…

CVE-2024-53991 HIGH 8 months, 3 weeks ago

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::Loca…

CVE-2024-47773 HIGH 11 months ago

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response …

CVE-2024-47772 MEDIUM 11 months ago

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a malicious…

CVE-2024-43789 HIGH 11 months ago

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once…

CVE-2024-45297 MEDIUM 11 months ago

Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This i…

CVE-2024-45051 HIGH 11 months ago

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based res…