VYPR

Bitnami package

discourse

pkg:bitnami/discourse

Vulnerabilities (274)

  • CVE-2026-33355MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not apply post-type visibility filtering, allowing regular PM participants to see whisper posts in PM topics they had access to. Version

  • CVE-2026-32099MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticated user could request a onebox

  • CVE-2026-29072HigMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right conditions. Versions 2026.3.0-lates

  • CVE-2026-28282MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any private/restricted groups. Once m

  • CVE-2026-27936MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versions 2026.3.0-latest.1, 2026.2.

  • CVE-2026-27935MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not have access to the private to

  • CVE-2026-27934HigMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized users, leading to information dis

  • CVE-2026-27740MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and renders it using htmlSafe in the R

  • CVE-2026-27570MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions 2026.3.0-latest.1, 2026.2.1, a

  • CVE-2026-27491MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only moderation feature. The vulnerabi

  • CVE-2026-27454MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_to directly without verifying whether the

  • CVE-2026-27166MedMar 19, 2026
    affected >= 2026.1.0, < 2026.1.2fixed 2026.1.2

    Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in

  • CVE-2026-28227LowFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publish topics into staff-only categories via the `publish_to_category` topic timer, bypassing authorization checks. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patc

  • CVE-2026-28219MedFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper authorization check in the topic management logic allows authenticated users to modify privileged attributes of their topics. By manipulating specific parameters in a

  • CVE-2026-28218MedFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignments, including built-in system queries.

  • CVE-2026-27154MedFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name can be evaluated as raw HTML when the following settings are set: `display_name_on_posts` => true; and `prioritize_username_in_ux` => false. Editing a post of a

  • CVE-2026-27153LowFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in `can_export_entity?`. The method allowed moderators to export an

  • CVE-2026-27162MedFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was checking topic access but then returning all posts regardless of type, including whispers that should only be visible to whisperers. Use `Post.secured(guardian

  • CVE-2026-27152LowFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddUsersToChannel` — a user could add targets who have blocked/ignored/muted them to an existing DM channel, byp

  • CVE-2026-27151LowFeb 26, 2026
    affected < 2025.12.2fixed 2025.12.2

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` action only checked `can_move_posts?` on the source topic but never validated write permissions on the destination topic. This allowed TL4 users and category gro

Page 5 of 14