CVE-2026-33073
- EPSS 0.18%
- Veröffentlicht 31.03.2026 17:38:59
- Zuletzt bearbeitet 10.04.2026 01:51:54
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a ...
CVE-2026-33428
- EPSS 0.27%
- Veröffentlicht 20.03.2026 23:21:20
- Zuletzt bearbeitet 24.03.2026 19:41:41
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group membership could access deleted posts belonging to any user due to an overly broad authorization check ...
CVE-2026-33427
- EPSS 0.21%
- Veröffentlicht 20.03.2026 23:20:03
- Zuletzt bearbeitet 24.03.2026 19:46:16
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a legitimate Discourse authorization page to display an attacker-controlled domain, facilitating socia...
CVE-2026-33426
- EPSS 0.16%
- Veröffentlicht 20.03.2026 23:14:57
- Zuletzt bearbeitet 24.03.2026 19:56:39
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users with tag-editing permissions could edit and create synonyms for tags hidden in restricted tag groups, even if they lacked visibility i...
CVE-2026-33425
- EPSS 0.21%
- Veröffentlicht 20.03.2026 23:12:30
- Zuletzt bearbeitet 24.03.2026 19:41:56
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenticated users can determine whether a specific user is a member of a private group by observing changes in directory results when us...
CVE-2026-33424
- EPSS 0.22%
- Veröffentlicht 20.03.2026 23:08:11
- Zuletzt bearbeitet 24.03.2026 19:38:59
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacker can grant access to a private message topic through invites even after they lose access to that PM. Versions 2026.3.0-latest.1, ...
CVE-2026-33423
- EPSS 0.2%
- Veröffentlicht 20.03.2026 23:06:21
- Zuletzt bearbeitet 25.03.2026 19:12:32
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, staff can modify any user's group notification level. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workaroun...
CVE-2026-33422
- EPSS 0.28%
- Veröffentlicht 20.03.2026 23:04:45
- Zuletzt bearbeitet 24.03.2026 21:11:46
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_address` of a flagged user is exposed to any user who can access the review queue, including users who should not be able to see IP...
CVE-2026-33411
- EPSS 0.21%
- Veröffentlicht 20.03.2026 22:58:14
- Zuletzt bearbeitet 24.03.2026 21:11:01
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a potential stored XSS in topic titles for the solved posts stream. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. ...
CVE-2026-33291
- EPSS 0.2%
- Veröffentlicht 20.03.2026 22:56:06
- Zuletzt bearbeitet 24.03.2026 21:10:46
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators can create Zendesk tickets for topics they do not have access to view. This affects all forums that use the Zendesk plugin. Versi...