VYPR

Discourse

by Discourse (software)

Source repositories

CVEs (285)

  • CVE-2026-28282MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any private/restricted groups. Once…

  • CVE-2026-27935MedMar 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not have access to the private…

  • CVE-2026-28218MedFeb 26, 2026
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignments, including built-in system queries.…

  • CVE-2026-26207MedFeb 26, 2026
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy` plugin allows any authenticated user to interact with policies on posts they do not have permission to view. The `PolicyController` loads posts by ID without…

  • CVE-2025-69289MedJan 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff accounts. This issue is patched…

  • CVE-2025-68660MedJan 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, an endpoint lets any authenticated user bypass the ai_discover_persona access controls and gain ongoing DM access to personas that may be wired to staff-only…

  • CVE-2023-32061MedJun 13, 2023
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide…

  • CVE-2023-30538MedApr 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacker can execute arbitrary JavaScript on the users’ browsers by uploading a crafted SVG file. This issue is patched in the latest stable and tests-passed…

  • CVE-2022-24850MedApr 14, 2022
    risk 0.35cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by anyone that has access to the category. As a result, a normal user is able to see whether a group has read/write permissions in the category even though the…

  • CVE-2026-72728MedAug 10, 2026
    risk 0.34cvss 6.3epss 0.00

    Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and…

  • CVE-2026-27021MedFeb 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked post visibility checks which allowed unauthorized access to voters details of polls in any post. Versions 2025.12.2, 2026.1.1, and…

  • CVE-2024-49765MedDec 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse.…

  • CVE-2024-45297MedOct 7, 2024
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade.…

  • CVE-2023-44391MedOct 16, 2023
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even when `hide_user_profiles_from_public` is enabled. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 version of Discourse. Users are advised to…

  • CVE-2023-23615MedFeb 3, 2023
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source discussion platform. The embeddable comments can be exploited to create new topics as any user but without any clear title or content. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. As a workaround, disable…

  • CVE-2022-39378MedNov 2, 2022
    risk 0.34cvss 5.3epss 0.01

    Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on a user's activity in a topic with restricted access. Before this vulnerability was disclosed, the topic title of the topic associated with the user badge may…

  • CVE-2026-32113MedMar 31, 2026
    risk 0.33cvss 6.1epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with…

  • CVE-2026-27740MedMar 19, 2026
    risk 0.33cvss 6.1epss 0.00

    Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and renders it using htmlSafe in the…

  • CVE-2026-27570MedMar 19, 2026
    risk 0.33cvss 6.1epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions 2026.3.0-latest.1, 2026.2.1,…

  • CVE-2024-39320MedJul 30, 2024
    risk 0.33cvss 6.1epss 0.00

    Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the intended restrictions enforced by the allowed_iframes setting. This vulnerability is fixed in 3.2.5 and…

Page 4 of 15