Vulnerabilidades em Discourse
308 resultadosAnálise Vexday
Discourse apresenta uma vulnerabilidade catalogada na base, sem evidência de exploração ativa em campo (0 KEV). A fraqueza identificada é CWE-862 (falta de autorização), risco moderado típico de controle de acesso. O panorama é estável, sem publicações recentes que indiquem degradação da postura de segurança.
CVE-2026-49256MEDIUMDiscourse: Hidden tag names leaked via category serializersEPSS 0.5%CVE-2023-22468HIGHDiscourse vulnerable to Cross-site Scripting in local oneboxesEPSS 0.5%CVE-2023-43658HIGHImproper escaping of user input in discourse-calendarEPSS 0.5%CVE-2023-23935LOWPresence of restricted personal Discourse messages may be leaked if tagged with a tag EPSS 0.5%CVE-2026-45780MEDIUMDiscourse: Private event sample invitees are serialized to non-invited event viewersEPSS 0.5%CVE-2023-25819MEDIUMDiscourse tags with no visibility are leaking into og:article:tagEPSS 0.5%CVE-2024-28242MEDIUMDisclosure of the existence of secret categories with custom backgrounds in DiscourseEPSS 0.5%CVE-2023-43657HIGHImproper escaping of encrypted topic titles can lead to Cross-site Scripting under non-default site configurationEPSS 0.5%CVE-2024-23834MEDIUMDiscourse improperly sanitized user input leads to XSSEPSS 0.5%CVE-2023-22455MEDIUMDiscourse vulnerable to Cross-site Scripting through tag descriptionsEPSS 0.5%CVE-2022-36057MEDIUMDiscourse-Chat Cross-Site Scripting issue for channel names and descriptionsEPSS 0.5%CVE-2023-38685MEDIUMDiscourse's restricted tag information visible to unauthenticated usersEPSS 0.5%CVE-2022-46180MEDIUMArbitrary HTML injection in discourse-mermaid-theme-componentEPSS 0.5%CVE-2022-41944LOWDiscourse users can see notifications for topics they no longer have access toEPSS 0.5%CVE-2024-38360MEDIUMDenial of service via Watched Words in DiscourseEPSS 0.5%CVE-2022-46148HIGHDiscourse allows self-XSS through malicious composer messageEPSS 0.5%CVE-2026-44787HIGHDiscourse: Signup-time primary_group_id assignment grants whisperer accessEPSS 0.5%CVE-2024-43789HIGHDenial of service by the absence of restrictions on replies to posts in DiscourseEPSS 0.5%CVE-2026-72724MEDIUMDiscourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID MismatchEPSS 0.5%CVE-2024-53851MEDIUMPartial denial of service via inline oneboxes in DiscourseEPSS 0.5%