All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.
This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.
Vendor: discourse
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-37693 | Re-use of email tokens in Discourse CWE-640 | 5.3 | Medium | 2021-08-13 |
| CVE-2021-37633 | XSS via d-popover and d-html-popover attribute CWE-79 | 7.4 | High | 2021-08-09 |
| CVE-2021-32788 | Post creator of a whisper post can be revealed to non-staff users in Discourse CWE-668 | 4.3 | Medium | 2021-07-27 |
| CVE-2021-32764 | YouTube Onebox susceptible to XSS CWE-79 | 8.1 | High | 2021-07-15 |
| CVE-2019-1020018 | Discourse 授权问题漏洞 | 5.3 | - | 2019-07-29 |
| CVE-2019-1020017 | Discourse 访问控制错误漏洞 | 5.3 | - | 2019-07-29 |
All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.