Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Discourse

First CVE: Jul 29, 2019Active for: 7 yearsTotal CVEs: 290
31.7
VTI Score
Medium

Discourse operates a widely deployed community and discussion platform that serves as a hosted or self-managed communication hub for organizations, forums, and customer communities. Despite a compact product portfolio centered on the core platform and extensions such as calendar and chat functionality, the vendor's vulnerability footprint is substantial and reflects the platform's prominent role in the web application landscape. The recurring exposure concentrates in information-disclosure, cross-site scripting, authorization, and input-validation weakness classes that are characteristic of feature-rich web applications handling user-generated content and authentication. Defenders should treat Discourse instances as high-value targets for regular patching, particularly those exposed to the internet or hosting sensitive community data; live severity and current exploitation counts are shown alongside this summary.

FAUCET AI Generated
290
Total CVEs
More Total CVEs than 100% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Discourse over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2019
6 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (290 CVEs).

290 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41163CRITICAL
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of v
Oct 20, 20219.840NONO
CVE-2026-53963CRITICAL
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escap
Jul 9, 20269.037NONO
CVE-2026-55420HIGH
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be e
Jul 9, 20268.136NONO
CVE-2024-53991MEDIUM
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and
Dec 19, 20245.936NOYES
CVE-2026-49256HIGH
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as
Jul 9, 20267.534NONO
CVE-2026-44787HIGH
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and
Jul 9, 20267.133NONO
CVE-2026-45788HIGH
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew
Jul 9, 20267.533NONO
CVE-2024-47773HIGH
Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. Thi
Oct 8, 20248.233NOYES
CVE-2023-45131HIGH
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3
Oct 16, 20237.532NOYES
CVE-2025-68662CRITICAL
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassi
Jan 28, 20269.931NONO
View all 290 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products290 CVEs
74%
16%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (0.7%)
Network288 (99.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low282 (97.2%)
High8 (2.8%)
Unknown0 (0.0%)
User Interaction
None226 (77.9%)
Unknown0 (0.0%)
Required64 (22.1%)
Privileges Required
Low133 (45.9%)
High29 (10.0%)
None128 (44.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (290 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
0.7% of CVEs· 95th percentile
ExploitDB
2 CVEs
0.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Discourse.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Discourse — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Discourse's Products

View all 3 CNAs →

Top CWEs