| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-26145 | Uninvited user is able to join and mark the attendance of the the private event | discourse | discourse-calendar | Medium | 6.5 | 2024-02-21 17:19:11 | Deep Dive |
| CVE-2023-46241 | Potential account take over due to unverified emails from Microsoft Identity Platform | discourse | discourse-microsoft-auth | Critical | 9.0 | 2024-02-21 16:08:41 | Deep Dive |
| CVE-2024-24755 | discourse-group-membership-ip-block is exposing potentially sensitive custom fields | discourse | discourse-group-membership-ip-block | Medium | 4.3 | 2024-02-01 22:14:23 | Deep Dive |
| CVE-2024-23834 | Discourse improperly sanitized user input leads to XSS | discourse | discourse | Medium | 6.3 | 2024-01-30 21:31:36 | Deep Dive |
| CVE-2023-49099 | Discourse secure uploads accessible to guests even when login is required | discourse | discourse | Low | 3.1 | 2024-01-12 20:53:53 | Deep Dive |
| CVE-2024-21655 | Insufficient control of custom field value sizes | discourse | discourse | Medium | 4.3 | 2024-01-12 20:46:00 | Deep Dive |
| CVE-2023-49098 | Reaction data for user notifications exposed in Discourse-reactions | discourse | discourse-reactions | Low | 3.5 | 2024-01-12 20:37:27 | Deep Dive |
| CVE-2023-48297 | Discourse vulnerable to unlimited mentioned users in message serializer | discourse | discourse | High | 8.6 | 2024-01-12 20:35:02 | Deep Dive |
| CVE-2023-47121 | Discourse SSRF vulnerability in Embedding | discourse | discourse | Low | 3.4 | 2023-11-10 15:13:42 | Deep Dive |
| CVE-2023-47120 | Discourse DoS through Onebox favicon URL | discourse | discourse | High | 7.5 | 2023-11-10 15:09:54 | Deep Dive |
| CVE-2023-47119 | HTML injection in oneboxed links | discourse | discourse | Medium | 5.3 | 2023-11-10 15:00:38 | Deep Dive |
| CVE-2023-46130 | Bypassing height value allowed in some theme components | discourse | discourse | Medium | 4.3 | 2023-11-10 14:54:49 | Deep Dive |
| CVE-2023-45816 | Unread bookmark reminder notifications that the user cannot access can be seen | discourse | discourse | Low | 3.3 | 2023-11-10 14:49:28 | Deep Dive |
| CVE-2023-45806 | Discourse vulnerable to DoS via Regexp Injection in Full Name | discourse | discourse | Medium | 4.3 | 2023-11-10 14:43:38 | Deep Dive |
| CVE-2023-43658 | Improper escaping of user input in discourse-calendar | discourse | discourse-calendar | High | 8.0 | 2023-10-16 21:28:57 | Deep Dive |
| CVE-2023-45131 | Unauthenticated access to new private chat messages in Discourse | discourse | discourse | High | 7.5 | 2023-10-16 21:24:11 | Deep Dive |
| CVE-2023-44391 | Prevent unauthorized access to summary details in Discourse | discourse | discourse | Medium | 5.3 | 2023-10-16 21:22:25 | Deep Dive |
| CVE-2023-44388 | Malicious requests can fill up the log files resulting in a deinal of service in Discourse | discourse | discourse | High | 7.5 | 2023-10-16 21:11:27 | Deep Dive |
| CVE-2023-43814 | Exposure of poll options and votes to unauthorized users in Discourse | discourse | discourse | Low | 3.7 | 2023-10-16 21:09:17 | Deep Dive |
| CVE-2023-43659 | Cross-site Scripting via email preview when CSP disabled in Discourse | discourse | discourse | High | 8.0 | 2023-10-16 21:05:32 | Deep Dive |