CVE-2026-45775
- EPSS 0.32%
- Veröffentlicht 12.06.2026 20:25:33
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an ...
CVE-2026-45085
- EPSS 0.21%
- Veröffentlicht 12.06.2026 20:25:09
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving...
CVE-2026-44785
- EPSS 0.19%
- Veröffentlicht 12.06.2026 20:24:39
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper only checks can_see? on the post being explained, n...
CVE-2026-44784
- EPSS 0.23%
- Veröffentlicht 12.06.2026 20:23:52
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not necessarily admins or moderators can view a group'...
CVE-2026-44783
- EPSS 0.15%
- Veröffentlicht 12.06.2026 20:23:14
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authenticated use...
CVE-2026-44782
- EPSS 0.19%
- Veröffentlicht 12.06.2026 20:23:01
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as the predicate for i...
CVE-2026-44780
- EPSS 0.19%
- Veröffentlicht 12.06.2026 20:22:45
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSerializer unconditionally included payload["raw_email"...
CVE-2026-44779
- EPSS 0.24%
- Veröffentlicht 12.06.2026 20:22:30
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose whisper translation audit logs. This issue has...
CVE-2026-44786
- EPSS 0.26%
- Veröffentlicht 12.06.2026 20:22:06
- Zuletzt bearbeitet 15.06.2026 20:58:40
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public category channels are published to MessageBus withou...
CVE-2026-34154
- EPSS 0.21%
- Veröffentlicht 19.05.2026 18:41:55
- Zuletzt bearbeitet 24.07.2026 09:10:00
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completi...