|
171
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#ta…
New
|
CWE-200
Information Exposure
|
CVE-2026-47264
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish c…
New
|
CWE-200
Information Exposure
|
CVE-2026-47263
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnera…
New
|
CWE-22
Path Traversal
|
CVE-2026-45775
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/discl…
New
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-45085
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
- |
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 are vulnerable to stored cross-site scripting via unsanitized user display name in draft version…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45014
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
7.6 |
HIGH
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow.…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45012
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
7.3 |
HIGH
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the Editor role can co…
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-45011
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
9.3 |
CRITICAL
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` pr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44990
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
7.5 |
HIGH
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public c…
New
|
CWE-200
Information Exposure
|
CVE-2026-44786
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper …
New
|
CWE-200
Information Exposure
|
CVE-2026-44785
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|