Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-55948 | 8.2 HIGH | Anonymous cache poisoning via XHR requests in Discourse |
| CVE-2025-23023 | 8.2 HIGH | Anonymous cache poisoning via request headers in Discourse |
| CVE-2024-56328 | 6.5 MEDIUM | HTMLi(XSS without CSP) via Onebox urls in Discourse |
| CVE-2025-22602 | 6.5 MEDIUM | Stored DOM-based XSS (without CSP) via video placeholders in Discourse |
| CVE-2024-53851 | 4.3 MEDIUM | Partial denial of service via inline oneboxes in Discourse |
| CVE-2024-53994 | 4.3 MEDIUM | Potential bypass of chat permissions in Discourse |
| CVE-2025-22601 | 3.1 LOW | Client Side Path Traversal using activate account route in Discourse |
| CVE-2024-56197 | 2.2 LOW | Users can see other user's tagged PMs in Discourse |
No comments yet