← Back

Discourse

discourse

290 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Discourse
discourse
Calendar
calendar
Message Bus
message_bus
Assign
assign
Discotoc
discotoc
Patreon
patreon
Mermaid
mermaid
Reactions
reactions
Discourse Jira
discourse_jira
Ai
ai

CVEs (290)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Discourse
1Discourse
Jun 17, 2026
Aug 26, 2021
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks. This is mitigated by Discourse's default Content Security Policy and t...Show more
Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross-site scripting(XSS) attacks. This is mitigated by Discourse's default Content Security Policy and this vulnerability only affects sites which have modified or disabled or changed Discourse's default Content Security Policy have allowed for moderators to modify categories. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.Show less
1Discourse
1Discourse
Jun 17, 2026
Aug 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a user's read state for a topic such as the last read post number and the notification level is exposed.
1Discourse
1Discourse
Jun 17, 2026
Aug 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is gener...Show more
Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on a Discourse site an email token is generated as part of the email verification process. Deleting the additional email address does not invalidate an unused token which can then be used in other contexts, including reseting a password.Show less
1Discourse
1Discourse
Jun 17, 2026
Aug 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discour...Show more
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched in the latest `stable` 2.7.8 version of Discourse. As a workaround users may ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.Show less
1Discourse
1Discourse
Jun 17, 2026
Jul 27, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post...Show more
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal message even though the whisper post cannot be seen by them. 2: When a whisper post is before the last post in a post stream, deleting the last post will result in the creator of the whisper post to be revealed to non-staff users as the last poster of the topic.Show less
1Discourse
1Discourse
Jun 17, 2026
Jul 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modifi...Show more
Discourse is an open-source discussion platform. In Discourse versions 2.7.5 and prior, parsing and rendering of YouTube Oneboxes can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. The issue is patched in `stable` version 2.7.6, `beta` version 2.8.0.beta3, and `tests-passed` version 2.8.0.beta3. As a workaround, ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.Show less
1Discourse
1Discourse
Jun 17, 2026
Jan 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
1Discourse
1Discourse
Jun 17, 2026
Aug 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Discourse 2.3.2 sends the CSRF token in the query string.
1Discourse
1Discourse
Jun 17, 2026
Jul 29, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
1Discourse
1Discourse
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.