Vulnerabilidades em Discourse

308 resultados
Análise Vexday

Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.

CVE-2024-52794MEDIUMMagnific lightbox susceptible to Cross-site Scripting in DiscourseEPSS 0.3%CVE-2025-68666MEDIUMDiscourse users archives leaked to users with moderation privilegesEPSS 0.3%CVE-2026-72729LOWDiscourse: Stored XSS in discourse-local-dates pluginEPSS 0.3%CVE-2026-30889MEDIUMDiscourse has Unauthorized Post Data Exposure in discourse-user-notesEPSS 0.3%CVE-2026-33408LOWDiscourse has Improper Authorization in "Post Edits" Report For ModeratorsEPSS 0.3%CVE-2023-37904LOWDiscourse Race Condition in Accept InviteEPSS 0.3%CVE-2026-33428MEDIUMDiscourse Allows Unauthorized Access to Deleted Posts Index via Group MembershipEPSS 0.3%CVE-2026-24742MEDIUMDiscourse staff action logs expose sensitive information to moderatorsEPSS 0.3%CVE-2026-27935MEDIUMDiscourse leaks private topic metadata to non-authorized usersEPSS 0.3%CVE-2023-45147MEDIUMArbitrary keys can be added to a topic's custom fields by any user in DiscourseEPSS 0.3%CVE-2023-45816LOWUnread bookmark reminder notifications that the user cannot access can be seenEPSS 0.3%CVE-2026-33422LOWDiscourse exposes ip_address of flagged userEPSS 0.3%CVE-2026-23743MEDIUMDiscourse allows permalinks to restricted resources to leak resource slugs to unauthorized usersEPSS 0.3%CVE-2025-48062HIGHDiscourse vulnerable to HTML injection when inviting to topic via emailEPSS 0.3%CVE-2026-44786HIGHDiscourse: Public chat MessageBus broadcasts are not restricted to chat-eligible usersEPSS 0.3%CVE-2024-55948HIGHAnonymous cache poisoning via XHR requests in DiscourseEPSS 0.3%CVE-2025-23023HIGHAnonymous cache poisoning via request headers in DiscourseEPSS 0.3%CVE-2024-45303MEDIUMDiscourse Calendar plugin event names susceptible to XSSEPSS 0.3%CVE-2024-43408MEDIUMDiscourse Placeholder Forms has a XSS stopped by CSPEPSS 0.3%CVE-2026-27934HIGHDiscourse leaks private topic title and post excerpt via user action API endpointEPSS 0.3%