Vulnerabilidades em Discourse
308 resultadosAnálise Vexday
Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.
CVE-2023-47119MEDIUMHTML injection in oneboxed linksEPSS 0.9%CVE-2021-41140MEDIUMReactions leak for secure category topics and private messagesEPSS 0.9%CVE-2026-27454MEDIUMDiscourse has check revision visibility on posts endpointEPSS 0.9%CVE-2021-32788MEDIUMPost creator of a whisper post can be revealed to non-staff users in DiscourseEPSS 0.9%CVE-2026-26265HIGHDiscourse has IDOR vulnerability in the directory items endpointEPSS 0.9%CVE-2023-22739MEDIUMDiscourse subject to Allocation of Resources Without Limits or ThrottlingEPSS 0.9%CVE-2023-23621HIGHDiscourse vulnerable to ReDoS in user agent parsingEPSS 0.9%CVE-2022-24804MEDIUMPrivate group name exposure in discourseEPSS 0.9%CVE-2022-39226MEDIUMDiscourse user profile location and website fields were not sufficiently length-limitedEPSS 0.9%CVE-2021-37703MEDIUMInformation exposure in DiscourseEPSS 0.8%CVE-2021-37693MEDIUMRe-use of email tokens in DiscourseEPSS 0.8%CVE-2022-39355CRITICALDiscourse Patreon vulnerable to improper validation of email during Patreon authenticationEPSS 0.8%CVE-2022-21684MEDIUMUser can bypass approval when invited to DiscourseEPSS 0.8%CVE-2021-43792MEDIUMNotifications leak in DiscourseEPSS 0.8%CVE-2021-43850MEDIUMDenial of Service in discourseEPSS 0.8%CVE-2021-43827MEDIUMInline footnotes wrapped in <a> tags can cause errors in discourse-footnotesEPSS 0.8%CVE-2023-46241CRITICALPotential account take over due to unverified emails from Microsoft Identity Platform EPSS 0.8%CVE-2022-21678MEDIUMUser's bio visible even if profile is restricted in DiscourseEPSS 0.8%CVE-2023-38706MEDIUMDiscourse vulnerable to DoS via draftsEPSS 0.8%CVE-2022-31182MEDIUMCache poisoning via maliciously-formed request in DiscourseEPSS 0.8%