Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.

Vendor: discourse

CVE ID Title CVSS Severity Published
CVE-2024-52794 Magnific lightbox susceptible to Cross-site Scripting in Discourse CWE-79 6.8 Medium 2024-12-19
CVE-2024-53991 Potential Backup file leaked via Nginx in Discourse CWE-200 7.5 High 2024-12-19
CVE-2024-47773 Anonymous cache poisoning via XHR requests in Discourse CWE-610 8.2 High 2024-10-08
CVE-2024-47772 Cross-site Scripting (XSS) via chat excerpts when content security policy (CSP) disabled in Discourse CWE-79 6.5 Medium 2024-10-07
CVE-2024-43789 Denial of service by the absence of restrictions on replies to posts in Discourse CWE-400 7.5 High 2024-10-07
CVE-2024-45297 Prevent topic list filtering by hidden tags for unauthorized users in Discourse CWE-269 5.3 Medium 2024-10-07
CVE-2024-45051 Bypass of email address validation via encoded email addresses in Discourse CWE-287 8.2 High 2024-10-07
CVE-2024-39320 Discourse allows iframe injection though default site setting CWE-74 6.1 Medium 2024-07-30
CVE-2024-37299 Discourse vulnerable to DoS via Tag Group CWE-400 4.9 Medium 2024-07-30
CVE-2024-37165 Discourse has an XSS via Onebox system CWE-79 6.3 Medium 2024-07-30
CVE-2024-38360 Denial of service via Watched Words in Discourse CWE-400 4.9 Medium 2024-07-15
CVE-2024-37157 Discourse vulnerable to Server-Side Request Forgery via FastImage CWE-918 6.4 Medium 2024-07-03
CVE-2024-36122 Discourse doesn't limit reviewable user serializer payload CWE-200 2.4 Low 2024-07-03
CVE-2024-36113 Discourse missing authorization checks for suspending admins/moderators CWE-862 4.9 Medium 2024-07-03
CVE-2024-35234 Discourse vulnerable to stored-dom XSS via Facebook Oneboxes CWE-79 4.2 Medium 2024-07-03
CVE-2024-35227 Discourse vulnerable to DoS through Onebox CWE-20 7.5 High 2024-07-03
CVE-2024-27085 Denial of service through invites in Discourse CWE-400 6.5 Medium 2024-03-15
CVE-2024-27100 Denial of service via Staff Actions in Discourse CWE-400 6.5 Medium 2024-03-15
CVE-2024-28242 Disclosure of the existence of secret categories with custom backgrounds in Discourse CWE-200 5.3 Medium 2024-03-15
CVE-2024-24748 Disclosure of the existence of secret subcategories in Discourse CWE-200 5.3 Medium 2024-03-15
CVE-2024-24827 No rate limits on POST /uploads endpoint in Discourse CWE-400 5.3 Medium 2024-03-15
CVE-2024-23834 Discourse improperly sanitized user input leads to XSS CWE-79 6.3 Medium 2024-01-30
CVE-2023-49099 Discourse secure uploads accessible to guests even when login is required CWE-284 3.1 Low 2024-01-12
CVE-2024-21655 Insufficient control of custom field value sizes CWE-400 4.3 Medium 2024-01-12
CVE-2023-48297 Discourse vulnerable to unlimited mentioned users in message serializer CWE-400 8.6 High 2024-01-12
CVE-2023-47121 Discourse SSRF vulnerability in Embedding CWE-918 3.4 Low 2023-11-10
CVE-2023-47120 Discourse DoS through Onebox favicon URL CWE-770 7.5 High 2023-11-10
CVE-2023-47119 HTML injection in oneboxed links CWE-74 5.3 Medium 2023-11-10
CVE-2023-46130 Bypassing height value allowed in some theme components CWE-770 4.3 Medium 2023-11-10
CVE-2023-45816 Unread bookmark reminder notifications that the user cannot access can be seen CWE-200 3.3 Low 2023-11-10

All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.