Vulnerabilidades en Discourse

308 resultados
Análisis Vexday

Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.

CVE-2025-48877HIGHDiscourse vulnerable to auto-executing of third-party code in embedded CodePen iframeEPSS 0.4%CVE-2022-41913MEDIUMDiscourse-calendar exposes members of hidden groupsEPSS 0.4%CVE-2025-46813MEDIUMPrivate data leak on login-required Discourse sitesEPSS 0.4%CVE-2023-34250MEDIUMDiscourse vulnerable to exposure of number of topics recently created in private categoriesEPSS 0.4%CVE-2023-36466LOWTopic Title Validation Skipped When Changing Category in DiscourseEPSS 0.4%CVE-2023-36473MEDIUMCSP nonce reuse vulnerability in DiscourseEPSS 0.4%CVE-2024-31219MEDIUMDiscourse-reactions' reaction data and public topic whisper content exposed on reactions given user activity pageEPSS 0.4%CVE-2024-26145MEDIUMUninvited user is able to join and mark the attendance of the the private eventEPSS 0.4%CVE-2023-30606MEDIUMMultisite denial of service through unsanitized dynamic dispatch to SiteSetting in DiscourseEPSS 0.4%CVE-2026-72723MEDIUMDiscourse: Anonymous sidebar serialization exposes descriptions of category-restricted tagsEPSS 0.4%CVE-2024-24755MEDIUMdiscourse-group-membership-ip-block is exposing potentially sensitive custom fieldsEPSS 0.4%CVE-2026-55674CRITICALDiscourse: Cache poisoning/XSS via color scheme cookiesEPSS 0.4%CVE-2025-49845MEDIUMDiscourse users are able to see their own whispers even after being removed from a group that has been configured to see whispersEPSS 0.4%CVE-2024-35168MEDIUMWordPress WP Discourse plugin <= 2.5.1 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-45051HIGHBypass of email address validation via encoded email addresses in DiscourseEPSS 0.4%CVE-2025-48053HIGHDiscourse vulnerable to DoS via large URL payload in PM to a botEPSS 0.4%CVE-2025-22601LOWClient Side Path Traversal using activate account route in DiscourseEPSS 0.4%CVE-2024-36122LOWDiscourse doesn't limit reviewable user serializer payloadEPSS 0.4%CVE-2025-24972MEDIUMDiscourse may bypass user preference when adding users to chat groupsEPSS 0.4%CVE-2023-37467MEDIUMDiscourse CSP nonce reuse vulnerability for anonymous usersEPSS 0.4%