CVE-2026-32618
- EPSS 0.2%
- Veröffentlicht 31.03.2026 17:40:41
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search withou...
CVE-2026-32619
- EPSS 0.16%
- Veröffentlicht 31.03.2026 17:40:41
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, users who lost access to a topic (e.g., removed from a private category gro...
CVE-2026-32615
- EPSS 0.15%
- Veröffentlicht 31.03.2026 17:40:17
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside...
CVE-2026-32607
- EPSS 0.17%
- Veröffentlicht 31.03.2026 17:40:05
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (default...
CVE-2026-32273
- EPSS 0.17%
- Veröffentlicht 31.03.2026 17:39:48
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description s...
CVE-2026-32243
- EPSS 0.17%
- Veröffentlicht 31.03.2026 17:39:38
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject...
CVE-2026-32113
- EPSS 0.19%
- Veröffentlicht 31.03.2026 17:39:25
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie a...
CVE-2026-32143
- EPSS 0.23%
- Veröffentlicht 31.03.2026 17:39:25
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing th...
CVE-2026-33073
- EPSS 0.18%
- Veröffentlicht 31.03.2026 17:38:59
- Zuletzt bearbeitet 24.07.2026 20:10:00
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a ...
CVE-2026-33428
- EPSS 0.27%
- Veröffentlicht 20.03.2026 23:21:20
- Zuletzt bearbeitet 24.03.2026 19:41:41
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group membership could access deleted posts belonging to any user due to an overly broad authorization check ...