CVE-2026-91119
- EPSS 0.2%
- Veröffentlicht 24.09.2026 17:07:04
- Zuletzt bearbeitet 28.09.2026 16:17:16
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attributes without...
- EPSS 0.26%
- Veröffentlicht 24.09.2026 17:05:20
- Zuletzt bearbeitet 24.09.2026 18:19:06
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and send chat conte...
CVE-2026-91120
- EPSS 0.2%
- Veröffentlicht 24.09.2026 17:00:05
- Zuletzt bearbeitet 24.09.2026 18:19:06
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse generated notification emails or chat summaries. A us...
CVE-2026-91132
- EPSS 0.14%
- Veröffentlicht 24.09.2026 16:57:43
- Zuletzt bearbeitet 29.09.2026 03:17:21
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could accept a crafted iframe URL whose allowlisted suffix appeared after a URL authori...
CVE-2026-91122
- EPSS 0.26%
- Veröffentlicht 24.09.2026 16:56:26
- Zuletzt bearbeitet 24.09.2026 18:19:06
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticate...
CVE-2026-91123
- EPSS 0.29%
- Veröffentlicht 24.09.2026 16:54:59
- Zuletzt bearbeitet 24.09.2026 18:19:06
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could therefore pas...
CVE-2026-91133
- EPSS 0.29%
- Veröffentlicht 24.09.2026 16:53:00
- Zuletzt bearbeitet 24.09.2026 18:19:07
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns, causing wildcard input to select unrelated upload ...
CVE-2026-91134
- EPSS 0.22%
- Veröffentlicht 24.09.2026 16:51:34
- Zuletzt bearbeitet 29.09.2026 03:17:21
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes prefix policy when the iframe src contained encoded ...
CVE-2026-84302
- EPSS 0.24%
- Veröffentlicht 24.09.2026 16:49:56
- Zuletzt bearbeitet 24.09.2026 18:19:03
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the...
CVE-2026-59830
- EPSS 0.17%
- Veröffentlicht 21.09.2026 21:17:38
- Zuletzt bearbeitet 23.09.2026 17:17:50
Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a crafted display ...