VYPR

Bitnami package

discourse

pkg:bitnami/discourse

Vulnerabilities (274)

  • CVE-2026-53962MedJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community brow

  • CVE-2026-53961MedJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account holde

  • CVE-2026-49256HigJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and unauthorized u

  • CVE-2026-46413MedJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and

  • CVE-2026-45788HigJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the secured upload URL and the secure_uploads site setting was enabled. This issue is fixed in vers

  • CVE-2026-45780MedJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to users who could view the topic but were not entitled to view the private event inv

  • CVE-2026-44787HigJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_gr

  • CVE-2026-55420HigJul 9, 2026
    affected >= 2026.1.0, < 2026.1.5fixed 2026.1.5

    Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 202

  • CVE-2026-47264MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag group a tag belonged to without filtering agains

  • CVE-2026-47263MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for /web_hook_events/ in Jobs::RedeliverWebHookEvents did not pass group_

  • CVE-2026-45775MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a path traversal vulnerability in Discourse backup handling could allow an authenticated administrator on

  • CVE-2026-45085MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving discourse-calendar): read-onl

  • CVE-2026-44786HigJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, chat events for public category channels are published to MessageBus without permission scoping, so any M

  • CVE-2026-44785MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the AI "explain" helper only checks can_see? on the post being explained, not its reply_to_post, so any a

  • CVE-2026-44784MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credenti

  • CVE-2026-44783MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, a flaw in how replies to whisper posts are handled allows authenticated users outside the groups configur

  • CVE-2026-44782MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as the predicate for its :name attribute, but AMS lo

  • CVE-2026-44780MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, ReviewableQueuedPostSerializer unconditionally included payload["raw_email"] for posts that arrived via i

  • CVE-2026-44779MedJun 12, 2026
    affected >= 2026.1.0, < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, bot debug endpoints disclose whisper translation audit logs. This issue has been patched in versions 2026

  • CVE-2026-34154MedMay 19, 2026
    affected < 2026.1.4fixed 2026.1.4

    Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has bee

Page 2 of 14