Discourse
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 319 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 29, 2019 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Discourse: Encode action_code_who in mention URLs
Discourse: Chat upload filenames rendered as raw HTML in excerpts
Discourse: Stored HTML injection in video notification emails
Discourse: Wildcard iframe origin allowlist bypass via authority separators
Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users
Discourse: Reject literal backslash path separators in iframe src traversal guard
Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure
Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlist
Discourse: Non-participant moderators can read, edit, and delete PM content through Discourse AI reviewables
Discourse: Shared-draft titles and excerpts leak through group post serialization
Monitor Discourse in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.