|
131
|
7.6 |
HIGH
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authenticated server-side request forgery (SSRF) in the rich-text widget import flow.…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45012
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
7.3 |
HIGH
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the Editor role can co…
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-45011
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
9.3 |
CRITICAL
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` pr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44990
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
7.5 |
HIGH
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public c…
New
|
CWE-200
Information Exposure
|
CVE-2026-44786
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper …
New
|
CWE-200
Information Exposure
|
CVE-2026-44785
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not…
New
|
CWE-200
Information Exposure
|
CVE-2026-44784
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to…
New
|
CWE-284
Improper Access Control
|
CVE-2026-44783
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer decl…
New
|
CWE-200
Information Exposure
|
CVE-2026-44782
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSeri…
New
|
CWE-200
Information Exposure
|
CVE-2026-44780
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disc…
New
|
CWE-200
Information Exposure
|
CVE-2026-44779
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|