CVE-2026-31869
- EPSS 0.03%
- Veröffentlicht 20.03.2026 03:15:59
- Zuletzt bearbeitet 24.03.2026 20:22:46
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the ComposerController#mentions endpoint reveals hidden group membership to any authenticated user who can message the group. By supplying a...
CVE-2026-30888
- EPSS 0.03%
- Veröffentlicht 20.03.2026 03:15:58
- Zuletzt bearbeitet 24.03.2026 19:59:16
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy documents (ToS, guidelines, privacy policy) that they are explicitly prohibited from modifying. Version...
CVE-2026-32114
- EPSS 0.03%
- Veröffentlicht 20.03.2026 03:13:34
- Zuletzt bearbeitet 24.03.2026 20:41:00
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access metadata about AI personas, f...
CVE-2026-33408
- EPSS 0.03%
- Veröffentlicht 19.03.2026 22:35:14
- Zuletzt bearbeitet 24.03.2026 20:55:00
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators were able to see the first 40 characters of post edits in PMs and private categories. Versions 2026.3.0-latest.1, 2026.2.1, and 2...
CVE-2026-33395
- EPSS 0.04%
- Veröffentlicht 19.03.2026 22:33:19
- Zuletzt bearbeitet 24.03.2026 19:46:59
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discourse-graphviz plugin contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious...
CVE-2026-33393
- EPSS 0.03%
- Veröffentlicht 19.03.2026 22:16:42
- Zuletzt bearbeitet 24.03.2026 20:41:57
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allowed_spam_host_domains` check used `String#end_with?` without domain boundary validation, allowing domains like `attacker-example.co...
CVE-2026-33394
- EPSS 0.03%
- Veröffentlicht 19.03.2026 22:16:42
- Zuletzt bearbeitet 24.03.2026 20:53:01
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure ...
CVE-2026-33355
- EPSS 0.01%
- Veröffentlicht 19.03.2026 22:01:42
- Zuletzt bearbeitet 24.03.2026 20:41:42
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not apply post-type visibility filtering, allowing regular PM participants to see whisper posts in PM topi...
CVE-2026-33410
- EPSS 0.03%
- Veröffentlicht 19.03.2026 21:57:27
- Zuletzt bearbeitet 24.03.2026 20:54:31
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the chat direct message API. First, when creating a direct message channel or adding users to an existing on...
CVE-2026-32099
- EPSS 0.01%
- Veröffentlicht 19.03.2026 21:52:24
- Zuletzt bearbeitet 24.03.2026 20:41:24
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticate...