Filter
-Infinity
0

Discourse Code Review PluginDiscourse Code Review Plugin vulnerable to XSS via auto link commits

3.1
First published (updated )

DiscoursePrivate data leak on login-required Discourse sites

EPSS
0.04%
First published (updated )

DiscourseDiscourse DM limits aren’t always properly enforced

First published (updated )

DiscourseExposure of whisper participants in discourse

First published (updated )

DiscourseUser's bio visible even if profile is restricted in Discourse

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseUser can bypass approval when invited to Discourse

8.8
First published (updated )

DiscourseGroup advanced search option may leak group and group's members visibility

First published (updated )

DiscourseDenial of Service in Discourse

First published (updated )

DiscourseSecure category names leaked via user activity export in Discourse

First published (updated )

DiscoursePrivate group name exposure in discourse

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseAnonymous user cache poisoning in discourse

First published (updated )

DiscourseCategory group permissions leaked in Discourse

First published (updated )

Discourse AssignExposure of Sensitive Information to an Unauthorized Actor in Discourse Assign

First published (updated )

DiscourseInvite bypasses user approval in Discourse

First published (updated )

Discourse Calendar pluginDiscourse Calendar Event names susceptible to Cross-site Scripting

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseBanner topic data is exposed on login-required Discourse sites

First published (updated )

DiscourseExposure of Sensitive Information in discourse-chat

First published (updated )

DiscourseInvites restricted to an email or invite links restricted to an email domain may be bypassed by a under certain conditions in Discourse

First published (updated )

DiscourseCache poisoning via maliciously-formed request in Discourse

First published (updated )

DiscourseEmail activation route can be abused by spammers in Discourse

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseDiscourse-Chat Cross-Site Scripting issue for channel names and descriptions

First published (updated )

DiscourseDiscourse vulnerable to RCE via admins uploading maliciously zipped file

First published (updated )

DiscourseDiscourse moderators can edit themes via the API

7.2
First published (updated )

DiscourseDiscourse user profile location and website fields were not sufficiently length-limited

First published (updated )

DiscourseDiscourse vulnerable to incomplete quote causing a topic to crash in the browser

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

DiscourseArbitrary HTML injection in table-of-contents theme component in DiscoTOC

First published (updated )

DiscourseDiscourse-chat plugin susceptible to XSS in channel name and description

First published (updated )

Discourse PatreonDiscourse Patreon vulnerable to improper validation of email during Patreon authentication

First published (updated )

DiscoursePossible Server-Side Request Forgery (SSRF) in webhooks

7.6
First published (updated )

DiscourseDiscourse user account takeover via email and invite link

8.9
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203