Discourse
Security Scorecard
Score
100A
Total CVEs
10
Patch Rate
90%
9 patched
Avg Response
-
days to patch
Critical Gaps
0
exploitable, no detection
Severity Breakdown
Critical0
High1
Medium9
Low0
Patch Status
Patched9 (90%)
Partial/Workaround1 (10%)
Unpatched0 (0%)
CVEs (10)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2025-66488 | Discourse S3 Upload Vulnerability | Medium | 4.6 | - | Patched |
| CVE-2025-67723 | Discourse Math Plugin XSS | Medium | 4.6 | - | Patched |
| CVE-2025-68659 | Discourse Denial of Service Vulnerability | Medium | 4.3 | - | Patched |
| CVE-2025-68662 | Discourse SSRF Bypass | High | 7.6 | - | Patched |
| CVE-2025-68933 | Discourse Server Privilege Escalation | Medium | 6.9 | - | Patched |
| CVE-2025-68934 | Discourse Discussion Platform Vulnerability | Medium | 6.5 | - | Patched |
| CVE-2026-24742 | Discourse Staff Action Log Bypass | Medium | 6.5 | - | Patched |
| CVE-2025-61598 | - | Medium | 5.3 | - | Patched |
| CVE-2025-59337 | - | Medium | 6.8 | - | Partial |
| CVE-2025-58055 | - | Medium | 4.3 | - | Patched |