CVE-2026-33410
- EPSS 0.16%
- Veröffentlicht 19.03.2026 21:57:27
- Zuletzt bearbeitet 24.03.2026 20:54:31
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the chat direct message API. First, when creating a direct message channel or adding users to an existing on...
CVE-2026-32099
- EPSS 0.3%
- Veröffentlicht 19.03.2026 21:52:24
- Zuletzt bearbeitet 24.03.2026 20:41:24
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticate...
CVE-2026-29072
- EPSS 0.23%
- Veröffentlicht 19.03.2026 21:49:33
- Zuletzt bearbeitet 23.03.2026 20:11:17
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right condi...
CVE-2026-28282
- EPSS 0.33%
- Veröffentlicht 19.03.2026 21:45:13
- Zuletzt bearbeitet 23.03.2026 20:16:43
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any pri...
CVE-2026-27936
- EPSS 0.31%
- Veröffentlicht 19.03.2026 21:42:36
- Zuletzt bearbeitet 23.03.2026 20:17:51
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versi...
CVE-2026-27935
- EPSS 0.27%
- Veröffentlicht 19.03.2026 21:33:38
- Zuletzt bearbeitet 23.03.2026 20:18:31
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not...
CVE-2026-27934
- EPSS 0.25%
- Veröffentlicht 19.03.2026 21:17:43
- Zuletzt bearbeitet 25.03.2026 21:04:13
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized use...
CVE-2026-27740
- EPSS 0.32%
- Veröffentlicht 19.03.2026 21:17:09
- Zuletzt bearbeitet 25.03.2026 00:58:33
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and rend...
CVE-2026-27570
- EPSS 0.35%
- Veröffentlicht 19.03.2026 20:52:17
- Zuletzt bearbeitet 25.03.2026 00:59:29
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions ...
CVE-2026-27491
- EPSS 0.33%
- Veröffentlicht 19.03.2026 20:47:54
- Zuletzt bearbeitet 25.03.2026 01:00:41
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only mod...