CVE-2026-33394
- EPSS 0.29%
- Veröffentlicht 19.03.2026 22:16:42
- Zuletzt bearbeitet 24.03.2026 20:53:01
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure ...
CVE-2026-33355
- EPSS 0.41%
- Veröffentlicht 19.03.2026 22:01:42
- Zuletzt bearbeitet 24.03.2026 20:41:42
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not apply post-type visibility filtering, allowing regular PM participants to see whisper posts in PM topi...
CVE-2026-33410
- EPSS 0.16%
- Veröffentlicht 19.03.2026 21:57:27
- Zuletzt bearbeitet 24.03.2026 20:54:31
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the chat direct message API. First, when creating a direct message channel or adding users to an existing on...
CVE-2026-32099
- EPSS 0.3%
- Veröffentlicht 19.03.2026 21:52:24
- Zuletzt bearbeitet 24.03.2026 20:41:24
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticate...
CVE-2026-29072
- EPSS 0.23%
- Veröffentlicht 19.03.2026 21:49:33
- Zuletzt bearbeitet 23.03.2026 20:11:17
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right condi...
CVE-2026-28282
- EPSS 0.33%
- Veröffentlicht 19.03.2026 21:45:13
- Zuletzt bearbeitet 23.03.2026 20:16:43
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any pri...
CVE-2026-27936
- EPSS 0.31%
- Veröffentlicht 19.03.2026 21:42:36
- Zuletzt bearbeitet 23.03.2026 20:17:51
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versi...
CVE-2026-27935
- EPSS 0.27%
- Veröffentlicht 19.03.2026 21:33:38
- Zuletzt bearbeitet 23.03.2026 20:18:31
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not...
CVE-2026-27934
- EPSS 0.25%
- Veröffentlicht 19.03.2026 21:17:43
- Zuletzt bearbeitet 25.03.2026 21:04:13
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized use...
CVE-2026-27740
- EPSS 0.32%
- Veröffentlicht 19.03.2026 21:17:09
- Zuletzt bearbeitet 25.03.2026 00:58:33
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and rend...