Filter
AND
-Infinity
0

Discourse MermaidArbitrary HTML injection in discourse-mermaid-theme-component

First published (updated )

DiscourseDiscourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch an…

First published (updated )

DiscourseDiscourse vulnerable to bypass of post max_length using HTML comments

First published (updated )

DiscourseDiscourse vulnerable to private topic leak via email#send_digest

First published (updated )

DiscourseDiscourse vulnerable to exposure of user post counts per topic to unauthorized users

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseDiscourse vulnerable to Cross-site Scripting through tag descriptions

First published (updated )

DiscourseDiscourse subject to Allocation of Resources Without Limits or Throttling

First published (updated )

DiscourseDiscourse membership requests lack character limit

First published (updated )

DiscourseDiscourse restricted tag routes leak topic information

First published (updated )

DiscourseDiscourse vulnerable to Allocation of Resources Without Limits via Chat drafts

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseDiscourse's exclude_tags param could leak which topics had a specific hidden tag

First published (updated )

DiscourseMalicious users in Discourse can create spam topics as any user due to improper access control

First published (updated )

DiscourseRegular expression denial of service via installing themes via git in discourse

First published (updated )

DiscourseDiscourse tags with no visibility are leaking into og:article:tag

First published (updated )

DiscourseYearly Review Plugin leaking anonymised users data in discourse-yearly-review

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscoursePresence of restricted personal Discourse messages may be leaked if tagged with a tag

First published (updated )

DiscourseDiscourse: Presence of read restricted topics may be leaked if tagged with a tag that is visible to all users

First published (updated )

DiscourseDiscourse chat messages susceptible to Cross-site Scripting through chat excerpts

First published (updated )

DiscourseDiscourse vulnerable to Cross-site Scripting - user name displayed on post

First published (updated )

DiscourseDiscourse vulnerable to multisite DoS by spamming backups

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseHTMLi(XSS without CSP) via Onebox urls in Discourse

First published (updated )

DiscourseStored DOM-based XSS (without CSP) via video placeholders in Discourse

First published (updated )

DiscourseMultisite denial of service through unsanitized dynamic dispatch to SiteSetting in Discourse

First published (updated )

DiscourseStored Cross-site Scripting via improper sanitization of svg files in Discourse

First published (updated )

DiscourseHTML injection via topic embedding in Discourse

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Discourse Calendar pluginUninvited user is able to join and mark the attendance of the the private event

EPSS
0.04%
First published (updated )

Discourse Calendar pluginUser can see invitees in events created in PMs and private categories

EPSS
0.04%
First published (updated )

Discourse ReactionsReaction metadata exposed in private topics in Discourse-reactions

First published (updated )

DiscourseCross-site Scripting (XSS) via topic titles when CSP disabled in Discourse

First published (updated )

DiscoursePartial denial of service via inline oneboxes in Discourse

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203