CVE-2026-53960
- EPSS 0.2%
- Veröffentlicht 17.08.2026 15:33:14
- Zuletzt bearbeitet 17.08.2026 16:16:58
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it ...
CVE-2026-55704
- EPSS 0.17%
- Veröffentlicht 17.08.2026 15:31:41
- Zuletzt bearbeitet 17.08.2026 22:17:14
Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the ...
CVE-2026-55674
- EPSS 0.34%
- Veröffentlicht 17.08.2026 15:30:17
- Zuletzt bearbeitet 18.08.2026 15:16:55
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Di...
CVE-2026-59829
- EPSS 0.23%
- Veröffentlicht 17.08.2026 15:26:53
- Zuletzt bearbeitet 17.08.2026 19:16:32
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag...
CVE-2026-72732
- EPSS 0.25%
- Veröffentlicht 10.08.2026 17:18:00
- Zuletzt bearbeitet 13.08.2026 18:18:16
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSerializer in plugins/discourse-templates/app/seriali...
CVE-2026-72731
- EPSS 0.23%
- Veröffentlicht 10.08.2026 16:25:23
- Zuletzt bearbeitet 10.08.2026 17:17:37
Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is shared with, co...
CVE-2026-72730
- EPSS 0.24%
- Veröffentlicht 10.08.2026 16:17:04
- Zuletzt bearbeitet 10.08.2026 19:17:33
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 20...
- EPSS 0.28%
- Veröffentlicht 10.08.2026 16:15:13
- Zuletzt bearbeitet 11.08.2026 03:18:01
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Polic...
CVE-2026-72728
- EPSS 0.19%
- Veröffentlicht 10.08.2026 16:13:20
- Zuletzt bearbeitet 10.08.2026 21:17:24
Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6...
CVE-2026-72727
- EPSS 0.23%
- Veröffentlicht 10.08.2026 16:08:21
- Zuletzt bearbeitet 13.08.2026 18:18:16
Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it...