Vulnerabilities > Discourse > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-10 CVE-2023-47121 Server-Side Request Forgery (SSRF) vulnerability in Discourse
Discourse is an open source platform for community discussion.
network
low complexity
discourse CWE-918
critical
9.8
2022-11-30 CVE-2022-46162 Cross-site Scripting vulnerability in Discourse Bbcode
discourse-bbcode is the official BBCode plugin for Discourse.
network
low complexity
discourse CWE-79
critical
9.8
2022-10-26 CVE-2022-39355 Improper Authentication vulnerability in Discourse Patreon
Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards.
network
low complexity
discourse CWE-287
critical
9.8
2021-10-20 CVE-2021-41163 Injection vulnerability in Discourse
Discourse is an open source platform for community discussion.
network
low complexity
discourse CWE-74
critical
9.8