Vulnerability Database

309,083

Total vulnerabilities in the database

CVE-2022-39356

Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with SiteSetting.max_invites_per_day = 0 or scope them to individual email addresses.

  • Published: Nov 2, 2022
  • Updated: Nov 16, 2025
  • CVE: CVE-2022-39356
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.9
  • AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Software From Fixed in
discourse / discourse 2.9.0-beta1 2.9.0-beta1.x
discourse / discourse 2.9.0-beta2 2.9.0-beta2.x
discourse / discourse 2.9.0-beta3 2.9.0-beta3.x
discourse / discourse 2.9.0-beta4 2.9.0-beta4.x
discourse / discourse 2.9.0-beta5 2.9.0-beta5.x
discourse / discourse 2.9.0-beta7 2.9.0-beta7.x
discourse / discourse 2.9.0-beta8 2.9.0-beta8.x
discourse / discourse 2.9.0-beta6 2.9.0-beta6.x
discourse / discourse 2.9.0-beta9 2.9.0-beta9.x
discourse / discourse 2.9.0-beta10 2.9.0-beta10.x
discourse / discourse - 2.8.10