Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.

Vendor: discourse

CVE ID Title CVSS Severity Published
CVE-2023-28107 Discourse vulnerable to multisite DoS by spamming backups CWE-770 4.5 Medium 2023-03-17
CVE-2023-25172 Discourse vulnerable to Cross-site Scripting - user name displayed on post CWE-79 4.4 Medium 2023-03-17
CVE-2023-26040 Discourse chat messages susceptible to Cross-site Scripting through chat excerpts CWE-79 6.5 Medium 2023-03-17
CVE-2023-23622 Discourse: Presence of read restricted topics may be leaked if tagged with a tag that is visible to all users CWE-200 4.3 Medium 2023-03-17
CVE-2023-23935 Presence of restricted personal Discourse messages may be leaked if tagged with a tag CWE-200 3.5 Low 2023-03-16
CVE-2023-25819 Discourse tags with no visibility are leaking into og:article:tag CWE-359 5.3 Medium 2023-03-04
CVE-2023-25167 Regular expression denial of service via installing themes via git in discourse CWE-1333 6.5 Medium 2023-02-08
CVE-2023-23615 Malicious users in Discourse can create spam topics as any user due to improper access control CWE-284 5.3 Medium 2023-02-03
CVE-2023-23624 Discourse's exclude_tags param could leak which topics had a specific hidden tag CWE-200 4.3 Medium 2023-01-27
CVE-2023-23621 Discourse vulnerable to ReDoS in user agent parsing CWE-1333 8.6 High 2023-01-27
CVE-2023-22740 Discourse vulnerable to Allocation of Resources Without Limits via Chat drafts CWE-770 4.3 Medium 2023-01-27
CVE-2023-23616 Discourse membership requests lack character limit CWE-400 3.5 Low 2023-01-27
CVE-2023-23620 Discourse restricted tag routes leak topic information CWE-200 5.3 Medium 2023-01-27
CVE-2023-22739 Discourse subject to Allocation of Resources Without Limits or Throttling CWE-770 6.5 Medium 2023-01-26
CVE-2023-22468 Discourse vulnerable to Cross-site Scripting in local oneboxes CWE-79 8.8 High 2023-01-26
CVE-2023-22455 Discourse vulnerable to Cross-site Scripting through tag descriptions CWE-79 6.8 Medium 2023-01-05
CVE-2023-22454 Discourse vulnerable to Cross-site Scripting through pending post titles descriptions CWE-79 8.0 High 2023-01-05
CVE-2023-22453 Discourse vulnerable to exposure of user post counts per topic to unauthorized users CWE-200 5.3 Medium 2023-01-05
CVE-2022-46177 Discourse password reset link can lead to in account takeover if user changes to a new email CWE-613 5.7 Medium 2023-01-05
CVE-2022-23546 Discourse vulnerable to private topic leak via email#send_digest CWE-200 5.5 Medium 2023-01-05
CVE-2022-46168 Group SMTP user emails are exposed in CC email header CWE-359 3.5 Low 2023-01-05
CVE-2022-23548 Discourse 跨站脚本漏洞 CWE-1333 6.5 Medium 2023-01-05
CVE-2022-23549 Discourse vulnerable to bypass of post max_length using HTML comments CWE-20 5.7 Medium 2023-01-05
CVE-2022-46159 Any authenticated Discourse user can create an unlisted topic CWE-770 4.3 Medium 2022-12-02
CVE-2022-46148 Discourse allows self-XSS through malicious composer message CWE-79 7.1 High 2022-11-29
CVE-2022-46150 Discourse may allow exposure of hidden tags in the subject of notification emails CWE-200 4.3 Medium 2022-11-29
CVE-2022-41921 Discourse chat messages should have a maximum character limit CWE-20 3.5 Low 2022-11-28
CVE-2022-41944 Discourse users can see notifications for topics they no longer have access to CWE-200 3.5 Low 2022-11-28
CVE-2022-39385 Users erroneously and transparently added to private messages in Discourse CWE-200 6.5 Medium 2022-11-14
CVE-2022-39241 Possible Server-Side Request Forgery (SSRF) in webhooks CWE-918 7.6 High 2022-11-02

All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.