VYPR

Bitnami package

discourse

pkg:bitnami/discourse

Vulnerabilities (274)

  • CVE-2026-59829MedAug 17, 2026
    affected < 2026.6.1fixed 2026.6.1

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and permalink) of the private message attached to a flag, even when the reviewing cate

  • CVE-2026-55704MedAug 17, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, could still receive shared-draft entries through the group posts and group mentions

  • CVE-2026-55674CriAug 17, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cook

  • CVE-2026-53960MedAug 17, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served Q&A (QAPage) JSON-LD structured data, exposing it to any unauthenticated visitor

  • CVE-2026-72732MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSerializer in plugins/discourse-templates/app/serializers/discourse_templates/templ

  • CVE-2026-72731HigAug 10, 2026
    affected < 2026.1.7fixed 2026.1.7

    Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is shared with, could craft parameter values tha

  • CVE-2026-72730HigAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

  • CVE-2026-72729LowAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in vers

  • CVE-2026-72728MedAug 10, 2026
    affected < 2026.1.7fixed 2026.1.7

    Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-lat

  • CVE-2026-72727MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or

  • CVE-2026-72726MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply stream. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

  • CVE-2026-72725MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

  • CVE-2026-72724MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/onebox_handler.rb resolves Chat::Thread by route thread_id independently of the route channel_id before checking whether the user can preview the selected c

  • CVE-2026-72723MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from SiteSetting.default_navigation_menu_tags without applying DiscourseTagging.filter_visible for the anony

  • CVE-2026-72722MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not consistently enforce Guardian.can_see? checks when processing internal links. An authent

  • CVE-2026-72721MedAug 10, 2026
    affected < 2026.1.6fixed 2026.1.6

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares hostnames and SiteSetting.blocked_onebox_domains entries case-sensitively, allowing an attacker to bypass configured Onebox domain rest

  • CVE-2026-72720MedAug 10, 2026
    affected < 2026.1.7fixed 2026.1.7

    Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.format_for_email because cooked attribute values are reparsed as markup. Crafted Vimeo iframe sources, secure-upload URLs or d

  • CVE-2026-59828MedJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in v

  • CVE-2026-55424MedJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the topic list, allowing a user who can set a featured link to inject JavaScript when

  • CVE-2026-53963HigJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator imp

Page 1 of 14