CVE-2024-53994

Potential bypass of chat permissions in Discourse

Discourse is an open source platform for community discussion. In affected versions users who disable chat in preferences could still be reachable in some cases. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable the chat plugin within site settings.


We have discovered 1,336 live websites that are affected by CVE-2024-53994.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains1,336 live websites (29% of Discourse install base)
Vulnerable Versions
  • from 0 through 3.3.2
Vulnerable Versions Count44 versions ( 77% of all versions)


Common Weakness Enumeration

CWE-281 Improper Preservation of Permissions



Details

  • Published - Feb 4, 2025
  • Updated - Feb 4, 2025

Website Distribution by Country

Number of websites using CVE-2024-53994
United States819 websites



Germany128 websites
France63 websites
Singapore35 websites
China30 websites
GB24 websites
Russia23 websites
Japan21 websites
Brazil18 websites
Netherlands15 websites

Website Distribution by TLD

Number of websites using CVE-2024-53994
.com555 websites
.org205 websites
.io66 websites
.net58 websites
.de31 websites
.ru20 websites
.fr19 websites
.co17 websites
.eu15 websites
.com.br11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-53994

Top websites that are affected by CVE-2024-53994. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States**,***
*********.******.com United States**,***
******.********.com United States**,***
*********.***************.com United States**,***
**************.org United States***,***
*****.*******.com United States***,***
*****.******.com United States***,***
*********.**********.de Germany***,***
*****.*********.com United States***,***
*****.******.cloud United States***,***
See full domain list

FAQ

CVE-2024-53994 is Improper Preservation of Permissions in Discourse
A total of 1,336 websites have been identified as vulnerable to CVE-2024-53994, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2024-53994 vulnerability.
Discourse versions up to and including 3.3.2 are vulnerable to CVE-2024-53994.