Vulnerabilidades en Discourse
308 resultadosAnálisis Vexday
Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.
CVE-2021-37633HIGHXSS via d-popover and d-html-popover attributeEPSS 0.8%CVE-2021-43793MEDIUMBypass of Poll voting limits in DiscourseEPSS 0.8%CVE-2022-36068HIGHDiscourse moderators can edit themes via the APIEPSS 0.8%CVE-2022-31059MEDIUMDiscourse Calendar Event names susceptible to Cross-site ScriptingEPSS 0.7%CVE-2026-53963HIGHDiscourse: Stored-XSS in 2FA delete confirmation modalEPSS 0.7%CVE-2022-23548MEDIUMDiscourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` andEPSS 0.7%CVE-2022-21642MEDIUMExposure of whisper participants in discourseEPSS 0.7%CVE-2025-48954HIGHDiscourse vulnerable to XSS via user-provided query parameter in oauth failure flowEPSS 0.7%CVE-2023-46130MEDIUMBypassing height value allowed in some theme componentsEPSS 0.7%CVE-2023-36818MEDIUMDenial of service via User Custom Sidebar Section Unlimited Link Creation in discourseEPSS 0.7%CVE-2023-38498MEDIUMDiscourse vulnerable to DoS via defer queueEPSS 0.7%CVE-2023-47121LOWDiscourse SSRF vulnerability in EmbeddingEPSS 0.7%CVE-2023-28440LOWDenial of service via admin theme import route in DiscourseEPSS 0.7%CVE-2023-22740MEDIUMDiscourse vulnerable to Allocation of Resources Without Limits via Chat draftsEPSS 0.7%CVE-2022-46177MEDIUMDiscourse password reset link can lead to in account takeover if user changes to a new emailEPSS 0.7%CVE-2023-23616LOWDiscourse membership requests lack character limitEPSS 0.7%CVE-2023-23620MEDIUMDiscourse restricted tag routes leak topic informationEPSS 0.7%CVE-2022-31184MEDIUMEmail activation route can be abused by spammers in DiscourseEPSS 0.7%CVE-2022-24850MEDIUMCategory group permissions leaked in DiscourseEPSS 0.7%CVE-2023-28107MEDIUMDiscourse vulnerable to multisite DoS by spamming backupsEPSS 0.7%