Filter
AND
-Infinity
0

DiscoursePrivate data leak on login-required Discourse sites

EPSS
0.04%
First published (updated )

DiscourseDiscourse DM limits aren’t always properly enforced

First published (updated )

DiscourseExposure of whisper participants in discourse

First published (updated )

DiscourseUser's bio visible even if profile is restricted in Discourse

First published (updated )

DiscourseGroup advanced search option may leak group and group's members visibility

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseDenial of Service in Discourse

First published (updated )

DiscourseSecure category names leaked via user activity export in Discourse

First published (updated )

DiscoursePrivate group name exposure in discourse

First published (updated )

DiscourseAnonymous user cache poisoning in discourse

First published (updated )

DiscourseCategory group permissions leaked in Discourse

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Discourse AssignExposure of Sensitive Information to an Unauthorized Actor in Discourse Assign

First published (updated )

DiscourseInvite bypasses user approval in Discourse

First published (updated )

Discourse Calendar pluginDiscourse Calendar Event names susceptible to Cross-site Scripting

First published (updated )

DiscourseBanner topic data is exposed on login-required Discourse sites

First published (updated )

DiscourseExposure of Sensitive Information in discourse-chat

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseInvites restricted to an email or invite links restricted to an email domain may be bypassed by a under certain conditions in Discourse

First published (updated )

DiscourseCache poisoning via maliciously-formed request in Discourse

First published (updated )

DiscourseDiscourse-Chat Cross-Site Scripting issue for channel names and descriptions

First published (updated )

DiscourseDiscourse user profile location and website fields were not sufficiently length-limited

First published (updated )

DiscourseDiscourse vulnerable to incomplete quote causing a topic to crash in the browser

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseArbitrary HTML injection in table-of-contents theme component in DiscoTOC

First published (updated )

DiscourseDiscourse-chat plugin susceptible to XSS in channel name and description

First published (updated )

DiscourseDisplaying user badges can leak topic titles to users that have no access to the topic

First published (updated )

DiscourseUsers erroneously and transparently added to private messages in Discourse

First published (updated )

Discourse Calendar pluginDiscourse-calendar exposes members of hidden groups

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseDiscourse chat messages should have a maximum character limit

First published (updated )

DiscourseDiscourse users can see notifications for topics they no longer have access to

First published (updated )

DiscourseDiscourse may allow exposure of hidden tags in the subject of notification emails

First published (updated )

DiscourseAny authenticated Discourse user can create an unlisted topic

First published (updated )

DiscourseDenial of Service in discourse

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203