📦 Discourse

by Discourse

🔍 What is Discourse?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53102

CRITICAL CVSS 9.8 Jul 29, 2025

Discourse versions before 3.4.7 and 3.5.0.beta8 have a session fixation vulnerability in WebAuthn 2FA implementation. When users authenticate with physical security keys, the server fails to clear the...

CVE-2025-48877

CRITICAL CVSS 9.8 Jun 9, 2025

This vulnerability in Discourse allows attackers to execute arbitrary JavaScript within iframes when Codepen is included in the allowed_iframes setting. It affects all Discourse instances using vulner...

CVE-2021-41163

CRITICAL CVSS 10.0 Oct 20, 2021

CVE-2021-41163 is a critical remote code execution vulnerability in Discourse that allows attackers to execute arbitrary code on affected servers through maliciously crafted webhook subscription URLs....

CVE-2026-23743

HIGH CVSS 7.5 Jan 28, 2026

This vulnerability in Discourse allows attackers to obtain sensitive information about private resources through URL redirects. When users without proper permissions access permalinks to restricted co...

CVE-2025-68662

HIGH CVSS 7.6 Jan 28, 2026

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Discourse's FinalDestination component where hostname validation can be bypassed under certain conditions. This allows attacker...

CVE-2025-68479

HIGH CVSS 7.1 Jan 28, 2026

This CVE describes an authorization bypass vulnerability in Discourse discussion platform where subscription endpoints lack proper ownership verification before allowing modifications. Attackers could...

CVE-2025-49845

HIGH CVSS 7.5 Jun 25, 2025

Discourse users on vulnerable versions can continue to view their own 'whisper' posts even after being removed from groups with whisper permissions. This creates an information disclosure vulnerabilit...

CVE-2025-48954

HIGH CVSS 8.1 Jun 25, 2025

Discourse versions before 3.5.0.beta6 are vulnerable to cross-site scripting (XSS) when social logins are used without Content Security Policy (CSP) enabled. This allows attackers to inject malicious ...

CVE-2025-48062

HIGH CVSS 7.1 Jun 9, 2025

This vulnerability allows HTML injection in Discourse email invitations when topic titles contain HTML. Attackers can inject malicious HTML into email bodies sent to users without accounts, potentiall...

CVE-2025-23023

HIGH CVSS 8.2 Feb 4, 2025

This vulnerability allows attackers to poison the anonymous cache in Discourse by crafting requests with specific headers, potentially causing visitors to receive incomplete or incorrect page content....

CVE-2024-55948

HIGH CVSS 8.2 Feb 4, 2025

This vulnerability allows attackers to poison the anonymous cache in Discourse through crafted XHR requests, potentially serving incomplete or manipulated content to anonymous visitors. Only anonymous...

CVE-2024-53991

HIGH CVSS 7.5 Dec 19, 2024

This vulnerability allows attackers to download Discourse backup files through nginx misconfiguration when using local storage. Only Discourse instances configured with FileStore::LocalStore for uploa...

CVE-2024-43789

HIGH CVSS 7.5 Oct 7, 2024

This vulnerability in Discourse allows authenticated users to create posts with many replies and then fetch them all at once, potentially causing denial of service by reducing instance availability. A...

CVE-2024-35227

HIGH CVSS 7.5 Jul 3, 2024

This vulnerability in Discourse allows attackers to reduce availability through a denial-of-service attack by exploiting improper input validation in the Onebox feature. Attackers can craft malicious ...

CVE-2023-48297

HIGH CVSS 8.6 Jan 12, 2024

Discourse's message serializer mishandles expanded chat mentions (@all and @here), creating excessively large user arrays that can cause denial of service. This affects all Discourse instances running...

CVE-2023-45131

HIGH CVSS 7.5 Oct 16, 2023

Discourse chat messages can be read by unauthenticated attackers via a POST request to MessageBus, exposing private conversations. This affects all Discourse instances running vulnerable versions. The...

CVE-2023-44388

HIGH CVSS 7.5 Oct 16, 2023

CVE-2023-44388 is a denial-of-service vulnerability in Discourse where malicious requests can rapidly fill production log files, causing servers to run out of disk space. This affects all Discourse ad...

CVE-2021-41082

HIGH CVSS 7.5 Sep 20, 2021

Discourse had a vulnerability where private message titles and participant lists were exposed to unauthorized users when groups were included in messages. The vulnerability affected Discourse instance...

CVE-2021-37633

HIGH CVSS 7.4 Aug 9, 2021

This Cross-Site Scripting (XSS) vulnerability in Discourse allows attackers to inject malicious scripts into d-popover tooltips, potentially compromising user sessions and data. Only sites that have m...

CVE-2026-24742

MEDIUM CVSS 6.5 Jan 28, 2026

This CVE allows non-admin moderators in Discourse to view sensitive information in staff action logs that should be restricted to administrators only. The exposed data includes webhook secrets, API ke...

CVE-2026-21865

MEDIUM CVSS 6.5 Jan 28, 2026

This vulnerability allows moderators in Discourse to improperly convert private personal messages into public topics, violating user privacy expectations. It affects Discourse instances running versio...

CVE-2025-69218

MEDIUM CVSS 6.5 Jan 28, 2026

This CVE allows moderators in Discourse to access the 'top_uploads' admin report, which should be restricted to administrators only. The report reveals direct URLs to all uploaded files, potentially e...

CVE-2025-69289

MEDIUM CVSS 5.4 Jan 28, 2026

A privilege escalation vulnerability in Discourse allows non-admin moderators to bypass email-change restrictions, potentially enabling account takeover of non-staff users. This affects Discourse inst...

CVE-2025-68666

MEDIUM CVSS 6.5 Jan 28, 2026

This CVE allows Discourse moderators to view user archives containing private topic/post content, violating confidentiality. It affects Discourse instances with versions prior to 3.5.4, 2025.11.2, 202...

CVE-2025-68933

MEDIUM CVSS 6.9 Jan 28, 2026

This CVE allows non-admin moderators with post ownership transfer permissions to change ownership of posts in private messages and restricted categories they cannot access, then export the data to vie...

CVE-2025-68934

MEDIUM CVSS 6.5 Jan 28, 2026

This vulnerability allows authenticated users to submit specially crafted payloads to Discourse's drafts endpoint, causing O(n^2) processing that ties up worker threads for 35-60 seconds per request. ...

CVE-2025-68659

MEDIUM CVSS 4.3 Jan 28, 2026

Discourse versions before 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application-level denial of service vulnerability in the username change functionality. Attackers can send large JSON payloa...

CVE-2025-68660

MEDIUM CVSS 5.4 Jan 28, 2026

This vulnerability in Discourse allows authenticated users to bypass AI persona access controls, gaining unauthorized access to staff-only AI personas and potentially sensitive data. Attackers can als...

CVE-2025-66488

MEDIUM CVSS 4.6 Jan 28, 2026

This vulnerability in Discourse allows attackers to upload HTML or XML files to S3 storage that can execute scripts in the context of the S3/CDN domain. It affects all Discourse instances using S3 for...

CVE-2025-67723

MEDIUM CVSS 4.6 Jan 28, 2026

This CVE describes a content-security-policy-mitigated cross-site scripting (XSS) vulnerability in Discourse's Math plugin when using the KaTeX variant. Attackers could potentially inject malicious sc...

CVE-2025-64528

MEDIUM CVSS 5.3 Dec 30, 2025

This vulnerability in Discourse allows attackers to discover users' full names even when the 'enable_names' setting is disabled, by using partial username knowledge through UI or API. It affects Disco...

CVE-2025-58055

MEDIUM CVSS 4.3 Oct 1, 2025

Discourse versions 3.5.0 and below contain an authorization bypass vulnerability in AI suggestion endpoints. Authenticated users can access restricted topic information by manipulating topic_id parame...

CVE-2025-46813

MEDIUM CVSS 5.8 May 5, 2025

This CVE describes a data leak vulnerability in Discourse where unauthenticated users could view private content on the homepage of login-required sites. Only sites deployed between specific commits o...

CVE-2025-32376

MEDIUM CVSS 4.3 Apr 30, 2025

This vulnerability allows attackers to bypass the user limit for direct messages (DMs) in Discourse, potentially creating DMs that include every user on a site. This affects all Discourse instances ru...

CVE-2025-24972

MEDIUM CVSS 4.3 Mar 26, 2025

Discourse users who disabled direct messaging in their preferences could still be added to group direct messages in specific circumstances. This affects Discourse instances running vulnerable versions...

CVE-2024-53851

MEDIUM CVSS 4.3 Feb 4, 2025

This vulnerability in Discourse allows authenticated users to send excessive URL requests to the inline onebox generation endpoint, causing denial of service to parts of the application. Only authenti...

CVE-2024-56328

MEDIUM CVSS 6.5 Feb 4, 2025

This CVE allows attackers to execute arbitrary JavaScript in users' browsers by posting malicious onebox URLs in Discourse forums. It affects Discourse sites with Content Security Policy (CSP) disable...

CVE-2025-22602

MEDIUM CVSS 6.5 Feb 4, 2025

This vulnerability allows attackers to execute arbitrary JavaScript in users' browsers by posting malicious video placeholder HTML elements in Discourse forums. Only Discourse sites with Content Secur...

CVE-2024-49765

MEDIUM CVSS 5.3 Dec 19, 2024

Discourse sites using Discourse Connect (SSO) with local logins still enabled are vulnerable to authentication bypass. Attackers can create accounts and log in without proper SSO validation. This affe...

CVE-2024-52794

MEDIUM CVSS 6.8 Dec 19, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in Discourse's lightbox thumbnail feature. When users click on lightbox thumbnails, malicious scripts could execute in their browsers. All...

CVE-2024-37299

MEDIUM CVSS 4.9 Jul 30, 2024

This vulnerability in Discourse allows attackers to submit extremely long tag group names in requests, which can cause resource exhaustion and reduce the availability of the platform. It affects all D...

CVE-2024-37157

MEDIUM CVSS 6.4 Jul 3, 2024

This vulnerability in Discourse allows attackers to manipulate the FastImage library to redirect requests to internal Discourse IP addresses, potentially enabling server-side request forgery (SSRF). A...

CVE-2024-36113

MEDIUM CVSS 4.9 Jul 3, 2024

This vulnerability allows a rogue staff user with administrative privileges in Discourse to suspend other staff users, preventing them from logging into the platform. It affects Discourse installation...