Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
{ "cpes": [ "cpe:2.3:a:discourse:discourse:2.3.2:*:*:*:*:*:*:*", "cpe:2.3:a:discourse:discourse:2.6.0:-:*:*:*:*:*:*" ], "severity": "Medium" }