Vulnerabilities in Discourse
308 resultsVexday analysis
Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.
CVE-2026-31805MEDIUMDiscourse has a poll authorization bypass via post_id array parameterEPSS 0.2%CVE-2025-68660MEDIUMDiscourse AI Discover's continue conversation allows threat actor to impersonate userEPSS 0.2%CVE-2026-27481MEDIUMDiscourse: Hidden tag visibility bypass on tag routesEPSS 0.2%CVE-2026-59829MEDIUMDiscourse: Review queue exposes flag-related private message excerpts to category group moderatorsEPSS 0.2%CVE-2025-68659MEDIUMDiscourse has DoS vulnerability in username change endpointEPSS 0.2%CVE-2026-27162MEDIUMDIscourse doesn't prevent whispers to leak in excerptsEPSS 0.2%CVE-2026-27149MEDIUMDiscourse has SQL injection in PM tag filteringEPSS 0.2%CVE-2026-26078HIGHDiscourse has authentication bypass vulnerability in the Patreon plugin webhook endpointEPSS 0.2%CVE-2026-30891MEDIUMDiscourse hasUnauthorized Exposure of Private User Action TypesEPSS 0.2%CVE-2026-30888LOWDiscourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpointEPSS 0.2%CVE-2026-33424MEDIUMPM access granted through invites after access revocationEPSS 0.2%CVE-2026-47264MEDIUMDiscourse: Don't leak restricted tag group names via tag infoEPSS 0.2%CVE-2026-72725MEDIUMDiscourse: Stored XSS in staff action logs injects staff UIEPSS 0.2%CVE-2026-34154LOWDiscourse has a subscription access bypass in its discourse-subscriptions pluginEPSS 0.2%CVE-2026-45085MEDIUMDiscourse: Chat misauthorization and information disclosureEPSS 0.2%CVE-2026-33395MEDIUMDiscourse has stored click‑based XSS via Graphviz SVG javascript: linksEPSS 0.2%CVE-2026-32114MEDIUMDiscourse's unscoped status lookups leak restricted metadataEPSS 0.2%CVE-2026-47263MEDIUMDiscourse: Prevent webhook payload disclosure on event redeliveryEPSS 0.2%CVE-2026-34947LOWDiscourse: Staged user custom fields are exposed on public invite pagesEPSS 0.2%CVE-2025-24808MEDIUMDiscourse has race condition when adding users to a group DMEPSS 0.2%