Vulnerabilidades en Discourse

308 resultados
Análisis Vexday

Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.

CVE-2023-22454HIGHDiscourse vulnerable to Cross-site Scripting through pending post titles descriptionsEPSS 0.6%CVE-2023-25167MEDIUMRegular expression denial of service via installing themes via git in discourseEPSS 0.6%CVE-2024-21655MEDIUMInsufficient control of custom field value sizesEPSS 0.6%CVE-2022-39241HIGHPossible Server-Side Request Forgery (SSRF) in webhooksEPSS 0.6%CVE-2024-27100MEDIUMDenial of service via Staff Actions in DiscourseEPSS 0.6%CVE-2023-28111MEDIUMDiscourse vulnerable to SSRF protection bypass possible with IPv4-mapped IPv6 addressesEPSS 0.6%CVE-2022-46150MEDIUMDiscourse may allow exposure of hidden tags in the subject of notification emailsEPSS 0.5%CVE-2021-32764HIGHYouTube Onebox susceptible to XSSEPSS 0.5%CVE-2026-59828MEDIUMDiscourse: Hidden post revisions leak through adjacent visible diffsEPSS 0.5%CVE-2022-39385MEDIUMUsers erroneously and transparently added to private messages in DiscourseEPSS 0.5%CVE-2023-37906MEDIUMDiscourse vulnerable to DoS via post edit reasonEPSS 0.5%CVE-2023-23622MEDIUMDiscourse: Presence of read restricted topics may be leaked if tagged with a tag that is visible to all usersEPSS 0.5%CVE-2023-44388HIGHMalicious requests can fill up the log files resulting in a deinal of service in DiscourseEPSS 0.5%CVE-2023-25172MEDIUMDiscourse vulnerable to Cross-site Scripting - user name displayed on postEPSS 0.5%CVE-2022-41921LOWDiscourse chat messages should have a maximum character limitEPSS 0.5%CVE-2022-46168LOWGroup SMTP user emails are exposed in CC email headerEPSS 0.5%CVE-2022-31096MEDIUMInvites restricted to an email or invite links restricted to an email domain may be bypassed by a under certain conditions in DiscourseEPSS 0.5%CVE-2022-39378MEDIUMDisplaying user badges can leak topic titles to users that have no access to the topicEPSS 0.5%CVE-2023-48297HIGHDiscourse vulnerable to unlimited mentioned users in message serializerEPSS 0.5%CVE-2026-46413MEDIUMDiscourse: Regular users can route multipart uploads into the admin backup storeEPSS 0.5%