Vulnerabilities in Discourse
308 resultsVexday analysis
Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.
CVE-2026-72722MEDIUMDiscourse: Duplicate lookup reveals restricted topic titles through canonicalized URLsEPSS 0.3%CVE-2026-27740MEDIUMDiscourse has Stored XSS in AI Triage AutomationEPSS 0.3%CVE-2026-45775MEDIUMDiscourse: Cross-site backup access via path traversal in multisite local backupsEPSS 0.3%CVE-2023-49099LOWDiscourse secure uploads accessible to guests even when login is requiredEPSS 0.3%CVE-2023-31142LOWDiscourse's general category permissions could be set back to defaultEPSS 0.3%CVE-2023-43814LOWExposure of poll options and votes to unauthorized users in DiscourseEPSS 0.3%CVE-2023-29196MEDIUMHTML injection via topic embedding in DiscourseEPSS 0.3%CVE-2025-68662HIGHFinalDestination hostname matching allows SSRF protection bypassEPSS 0.3%CVE-2023-49098LOWReaction data for user notifications exposed in Discourse-reactionsEPSS 0.3%CVE-2026-27936MEDIUMDiscourse discloses restricted post-action counts to non-privileged usersEPSS 0.3%CVE-2026-32099MEDIUMDiscourse prevents hidden profile data leak via user oneboxEPSS 0.3%CVE-2026-53961MEDIUMDiscourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)EPSS 0.3%CVE-2026-72720MEDIUMDiscourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsingEPSS 0.3%CVE-2025-59337MEDIUMDiscourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite DeploymentsEPSS 0.3%CVE-2024-53994MEDIUMPotential bypass of chat permissions in DiscourseEPSS 0.3%CVE-2025-61598MEDIUMDiscourse is missing Cache-Control response header on error responsesEPSS 0.3%CVE-2025-64528MEDIUMUsers are able to find users by name even when `enable_names` is offEPSS 0.3%CVE-2026-27021MEDIUMDiscourse: Poll voters endpoint lacked post visibility checksEPSS 0.3%CVE-2022-23546MEDIUMDiscourse vulnerable to private topic leak via email#send_digestEPSS 0.3%CVE-2024-53266MEDIUMCross-site Scripting (XSS) via topic titles when CSP disabled in DiscourseEPSS 0.3%