VYPR
Medium severityNVD Advisory· Published Jul 27, 2026

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

CVE-2023-37465

Description

Impact

It's possible to forge a request to delete a message.

Patches

The problem has been patched in version 2.0-rc-1 of Discussion Extension.

Workarounds

There's no easy workaround except upgrading.

### References https://jira.xwiki.org/browse/DISCUSSION-22

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira XWiki * Email us at security mailing-list

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.xwiki.contrib:discussions-serverMaven
< 2.0-rc-12.0-rc-1

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.