Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.

Vendor: discourse

CVE ID Title CVSS Severity Published
CVE-2025-68479 Discourse subscriptions are susceptible to takeover CWE-862 7.1 High 2026-01-28
CVE-2025-67723 Discourse vulnerable to stored Cross-site Scripting via Katex in discourse-math plugin CWE-79 4.6 Medium 2026-01-28
CVE-2025-66488 Discourse allows script execution in uploaded HTML/XML files on S3 CWE-116 4.6 Medium 2026-01-28
CVE-2025-64528 Users are able to find users by name even when `enable_names` is off CWE-202 5.3 - 2025-12-30
CVE-2025-61598 Discourse is missing Cache-Control response header on error responses CWE-524 5.3AI Medium AI 2025-10-28
CVE-2025-59337 Discourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite Deployments CWE-77 8.1AI High AI 2025-10-01
CVE-2025-58055 Discourse AI Suggestions Contain Insecure Direct Object Reference CWE-284 4.3 Medium 2025-10-01
CVE-2025-58054 Discourse is vulnerable to XSS when quoting chat messages CWE-80 3.5 Low 2025-10-01
CVE-2025-54411 Discourse welcome banner user name XSS CWE-79 5.4AI Medium AI 2025-08-19
CVE-2025-53102 Discourse's WebAuthn challenge isn't cleared from user session after authentication CWE-384 8.2AI High AI 2025-07-29
CVE-2025-49845 Discourse users are able to see their own whispers even after being removed from a group that has been configured to see whispers CWE-200 4.3AI Medium AI 2025-06-25
CVE-2025-48954 Discourse vulnerable to XSS via user-provided query parameter in oauth failure flow CWE-79 8.1 High 2025-06-25
CVE-2025-48877 Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe CWE-1038 5.4AI Medium AI 2025-06-09
CVE-2025-48062 Discourse vulnerable to HTML injection when inviting to topic via email CWE-116 7.1 High 2025-06-09
CVE-2025-48053 Discourse vulnerable to DoS via large URL payload in PM to a bot CWE-400 4.3AI Medium AI 2025-06-09
CVE-2025-46813 Private data leak on login-required Discourse sites CWE-200 5.8 Medium 2025-05-05
CVE-2025-32376 Discourse DM limits aren’t always properly enforced CWE-284 4.3AI Medium AI 2025-04-30
CVE-2025-24972 Discourse may bypass user preference when adding users to chat groups CWE-862 4.3 Medium 2025-03-26
CVE-2025-24808 Discourse has race condition when adding users to a group DM CWE-362 4.3 Medium 2025-03-26
CVE-2024-53266 Cross-site Scripting (XSS) via topic titles when CSP disabled in Discourse CWE-79 4.3 Medium 2025-02-04
CVE-2024-53851 Partial denial of service via inline oneboxes in Discourse CWE-400 4.3 Medium 2025-02-04
CVE-2024-53994 Potential bypass of chat permissions in Discourse CWE-281 4.3 Medium 2025-02-04
CVE-2024-55948 Anonymous cache poisoning via XHR requests in Discourse CWE-346 8.2 High 2025-02-04
CVE-2024-56197 Users can see other user's tagged PMs in Discourse CWE-200 2.2 Low 2025-02-04
CVE-2024-56328 HTMLi(XSS without CSP) via Onebox urls in Discourse CWE-79 6.5 Medium 2025-02-04
CVE-2025-22601 Client Side Path Traversal using activate account route in Discourse CWE-22 3.1 Low 2025-02-04
CVE-2025-22602 Stored DOM-based XSS (without CSP) via video placeholders in Discourse CWE-79 6.5 Medium 2025-02-04
CVE-2025-23023 Anonymous cache poisoning via request headers in Discourse CWE-346 8.2 High 2025-02-04
CVE-2024-49765 Bypass of Discourse Connect using other login paths if enabled in Discourse CWE-359 5.3 Medium 2024-12-19
CVE-2024-52589 Moderators can view Screened emails even when the “moderators view emails” option is disabled in Discourse CWE-200 2.2 Low 2024-12-19

All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.