Medium severityNVD Advisory· Published Jul 27, 2026
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
CVE-2023-37465
Description
Impact
It's possible to forge a request to delete a message.
Patches
The problem has been patched in version 2.0-rc-1 of Discussion Extension.
Workarounds
There's no easy workaround except upgrading.
### References https://jira.xwiki.org/browse/DISCUSSION-22
For more information
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki * Email us at security mailing-list
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.xwiki.contrib:discussions-serverMaven | < 2.0-rc-1 | 2.0-rc-1 |
Affected products
1- Range: <2.0-rc-1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.