CVE-2026-44787
- EPSS 0.27%
- Veröffentlicht 09.07.2026 22:03:41
- Zuletzt bearbeitet 14.07.2026 20:44:55
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on ...
CVE-2026-53962
- EPSS 0.3%
- Veröffentlicht 09.07.2026 22:02:27
- Zuletzt bearbeitet 14.07.2026 01:35:33
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not n...
CVE-2026-55424
- EPSS 0.3%
- Veröffentlicht 09.07.2026 22:01:22
- Zuletzt bearbeitet 14.07.2026 01:26:52
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured ...
CVE-2026-45788
- EPSS 0.47%
- Veröffentlicht 09.07.2026 21:59:27
- Zuletzt bearbeitet 14.07.2026 20:41:53
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enable...
CVE-2026-49256
- EPSS 0.37%
- Veröffentlicht 09.07.2026 21:56:40
- Zuletzt bearbeitet 14.07.2026 20:40:56
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak t...
CVE-2026-46413
- EPSS 0.37%
- Veröffentlicht 09.07.2026 21:55:45
- Zuletzt bearbeitet 14.07.2026 20:41:29
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 202...
CVE-2026-53961
- EPSS 0.23%
- Veröffentlicht 09.07.2026 21:48:11
- Zuletzt bearbeitet 14.07.2026 20:37:07
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, ...
CVE-2026-55420
- EPSS 0.35%
- Veröffentlicht 09.07.2026 17:54:07
- Zuletzt bearbeitet 14.07.2026 02:16:56
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6....
CVE-2026-47264
- EPSS 0.22%
- Veröffentlicht 12.06.2026 20:26:38
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag group a tag belong...
CVE-2026-47263
- EPSS 0.21%
- Veröffentlicht 12.06.2026 20:26:19
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for /web_hook_events/<id> in Jobs::RedeliverWeb...