Home / CVEs we hold for Discourse CVEs we hold for Discourse Records whose assigning authority named Discourse as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-72732 Discourse: Templates endpoint exposes hidden tag names discourse CVE-2026-72731 Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer discourse CVE-2026-72730 Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor discourse CVE-2026-72729 Discourse: Stored XSS in discourse-local-dates plugin discourse CVE-2026-72728 Discourse: Onebox iframe origin allowlist enforces URL authority boundary discourse CVE-2026-72727 Discourse: Stored XSS in the moderation review queue discourse CVE-2026-72726 Discourse: Unauthorized eavesdropping on private AI bot conversations. discourse CVE-2026-72725 Discourse: Stored XSS in staff action logs injects staff UI discourse CVE-2026-72724 Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch discourse CVE-2026-72723 Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tags discourse CVE-2026-72722 Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs discourse CVE-2026-72721 Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison discourse CVE-2026-72720 Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing discourse CVE-2026-59829 Discourse: Review queue exposes flag-related private message excerpts to category group moderators discourse CVE-2026-59828 Discourse: Hidden post revisions leak through adjacent visible diffs discourse CVE-2026-55704 Discourse: Shared-draft titles and excerpts leak through group post serialization discourse CVE-2026-55674 Discourse: Cache poisoning/XSS via color scheme cookies discourse CVE-2026-55424 Discourse: Topic featured link susceptible to stored XSS discourse CVE-2026-55420 Discourse: Remote code execution via pdf uploads discourse CVE-2026-53963 Discourse: Stored-XSS in 2FA delete confirmation modal discourse CVE-2026-53961 Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding) discourse CVE-2026-53960 Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD discourse CVE-2026-49256 Discourse: Hidden tag names leaked via category serializers discourse CVE-2026-47264 Discourse: Don't leak restricted tag group names via tag info discourse CVE-2026-47263 Discourse: Prevent webhook payload disclosure on event redelivery discourse CVE-2026-46413 Discourse: Regular users can route multipart uploads into the admin backup store discourse CVE-2026-45788 Discourse: Secure uploads exposed by hotlinked image copying discourse CVE-2026-45780 Discourse: Private event sample invitees are serialized to non-invited event viewers discourse CVE-2026-45775 Discourse: Cross-site backup access via path traversal in multisite local backups discourse CVE-2026-45085 Discourse: Chat misauthorization and information disclosure discourse CVE-2026-44787 Discourse: Signup-time primary_group_id assignment grants whisperer access discourse CVE-2026-44786 Discourse: Public chat MessageBus broadcasts are not restricted to chat-eligible users discourse CVE-2026-44785 Discourse: Hidden reply-to post raw can be disclosed through AI explain prompts discourse CVE-2026-44784 Discourse: Non-staff group owners can see email password in plaintext through group history discourse CVE-2026-44783 Discourse: Replying to a whisper lets non-whisperers create staff-only whisper posts discourse CVE-2026-44782 Discourse: GroupPostSerializer leaks hidden full names through reaction post association discourse CVE-2026-44780 Discourse: Category queue reviewers can read raw incoming emails from queued posts discourse CVE-2026-44779 Discourse: Bot debug endpoints disclose whisper translation audit logs discourse CVE-2026-34947 Discourse: Staged user custom fields are exposed on public invite pages discourse CVE-2026-34154 Discourse has a subscription access bypass in its discourse-subscriptions plugin discourse CVE-2026-33514 Discourse: Information Disclosure in Form Template API Due to Missing Authorization discourse CVE-2026-33428 Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership discourse CVE-2026-33427 Discourse Authorization Page Displays Unvalidated Redirect Domain discourse CVE-2026-33426 Discourse users can edit or synonymize hidden tags they can't see discourse CVE-2026-33425 Discourse has inferable private group membership or existence via exclude_groups parameter discourse CVE-2026-33424 PM access granted through invites after access revocation discourse CVE-2026-33423 Discourse staff can modify any user's group notification level discourse CVE-2026-33415 Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure discourse CVE-2026-33411 Discourse's solved topic stream has potential stored XSS in topic title discourse CVE-2026-33410 Discourse hardens chat DM channel creation and expansion discourse CVE-2026-33408 Discourse has Improper Authorization in "Post Edits" Report For Moderators discourse CVE-2026-33395 Discourse has stored click‑based XSS via Graphviz SVG javascript: links discourse CVE-2026-33393 Discourse fixes loose hostname matching in spam host allowlist discourse CVE-2026-33355 Discourse filters whisper posts from private-posts feed discourse CVE-2026-33300 Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint discourse CVE-2026-33291 Discourse user can create Zendesk tickets even when it does not have access to topic discourse CVE-2026-33251 Discourse has a Hidden Solved topics permission bypass discourse CVE-2026-33185 Discourse: Group SMTP test endpoint susceptible to SSRF discourse CVE-2026-33074 Discourse: Vulnerability in discourse-subscriptions plugin allowing users to self-grant to higher tier subscriptions discourse CVE-2026-33073 discourse-subscriptions plugin leaking stripe API key in multisite environment discourse CVE-2026-32951 Discourse: Authorization bypass in oneboxer via user-controlled category id discourse CVE-2026-32620 Discourse: Missing post-level authorization allows whisper metadata disclosure discourse CVE-2026-32619 Discourse: Insufficient topic visibility check allows unauthorized poll manipulation in private categories discourse CVE-2026-32618 Discourse: Unauthorized channel membership inference via excluded_memberships_channel_id discourse CVE-2026-32615 Discourse: Category group moderators can perform actions on topics in restricted categories without read access discourse CVE-2026-32607 Discourse: Stored XSS via unescaped assignee name discourse CVE-2026-32273 Discourse: XSS on category description update via API discourse CVE-2026-32244 Discourse: Cached outdated summaries can leak removed content discourse CVE-2026-32243 Discourse: Stored XSS in discourse-ai shared conversations onebox discourse CVE-2026-32143 Discourse: Admin-only report can be exported by moderators discourse CVE-2026-32114 Discourse's unscoped status lookups leak restricted metadata discourse CVE-2026-32113 Discourse: Open redirect via `sso_destination_url` cookie in `enter` discourse CVE-2026-32099 Discourse prevents hidden profile data leak via user onebox discourse CVE-2026-31869 Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check discourse CVE-2026-31805 Discourse has a poll authorization bypass via post_id array parameter discourse CVE-2026-30891 Discourse hasUnauthorized Exposure of Private User Action Types discourse CVE-2026-30889 Discourse has Unauthorized Post Data Exposure in discourse-user-notes discourse CVE-2026-30888 Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpoint discourse CVE-2026-29072 Discourse missing permission check for policy creation in discourse-policy discourse CVE-2026-28282 Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin discourse CVE-2026-28227 Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Timer publish_to_category discourse CVE-2026-28219 Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Banners discourse CVE-2026-28218 Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution discourse CVE-2026-27936 Discourse discloses restricted post-action counts to non-privileged users discourse CVE-2026-27935 Discourse leaks private topic metadata to non-authorized users discourse CVE-2026-27934 Discourse leaks private topic title and post excerpt via user action API endpoint discourse CVE-2026-27740 Discourse has Stored XSS in AI Triage Automation discourse CVE-2026-27570 Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox discourse CVE-2026-27491 Discourse has a bypass of official warnings messages by non-staff users discourse CVE-2026-27481 Discourse: Hidden tag visibility bypass on tag routes discourse CVE-2026-27454 Discourse has check revision visibility on posts endpoint discourse CVE-2026-27166 Discourse vulnerable to HTML injection via prohibited iframe URLs discourse CVE-2026-27162 DIscourse doesn't prevent whispers to leak in excerpts discourse CVE-2026-27154 Discourse has XSS when editing a malicious post discourse CVE-2026-27153 Discourse doesn't prevent moderators from exporting user Chat DMs discourse CVE-2026-27152 DIscourse has DM communication-preference bypass when adding members discourse CVE-2026-27151 Discourse doesn't validate destination topic when moving posts discourse CVE-2026-27150 Discourse doesn't ensure guardian check when creating QueryGroupBookmark discourse CVE-2026-27149 Discourse has SQL injection in PM tag filtering discourse CVE-2026-27021 Discourse: Poll voters endpoint lacked post visibility checks discourse CVE-2026-26979 Discourse: TL4 users are able to change status of restricted topics discourse CVE-2026-26973 Discourse doesn't scope reviewable notes to user-visible reviewables discourse CVE-2026-26265 Discourse has IDOR vulnerability in the directory items endpoint discourse CVE-2026-26207 DIscourse's discourse-policy plugin lacks post access check discourse CVE-2026-26078 Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint discourse CVE-2026-26077 Discourse doesn't ensure webhooks require a token discourse CVE-2026-24742 Discourse staff action logs expose sensitive information to moderators discourse CVE-2026-23743 Discourse allows permalinks to restricted resources to leak resource slugs to unauthorized users discourse CVE-2026-21865 Discourse topic conversion permission vulnerability for moderators discourse CVE-2025-69289 Discourse has insecure default configuration that allows non-admin moderators to takeover any non-staff account via… discourse CVE-2025-69218 Discourse moderators can access admin-only reports exposing private upload URLs discourse CVE-2025-68934 Discourse Has Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint discourse CVE-2025-68933 Discourse non-admin moderators can exfiltrate private content via post ownership transfer discourse CVE-2025-68666 Discourse users archives leaked to users with moderation privileges discourse CVE-2025-68662 FinalDestination hostname matching allows SSRF protection bypass discourse CVE-2025-68660 Discourse AI Discover's continue conversation allows threat actor to impersonate user discourse CVE-2025-68659 Discourse has DoS vulnerability in username change endpoint discourse CVE-2025-68479 Discourse subscriptions are susceptible to takeover discourse CVE-2025-67723 Discourse vulnerable to stored Cross-site Scripting via Katex in discourse-math plugin discourse CVE-2025-66488 Discourse allows script execution in uploaded HTML/XML files on S3 discourse CVE-2025-64528 Users are able to find users by name even when `enable_names` is off discourse CVE-2025-61598 Discourse is missing Cache-Control response header on error responses discourse CVE-2025-59337 Discourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite Deployments discourse CVE-2025-58055 Discourse AI Suggestions Contain Insecure Direct Object Reference discourse CVE-2025-58054 Discourse is vulnerable to XSS when quoting chat messages discourse CVE-2025-53102 Discourse's WebAuthn challenge isn't cleared from user session after authentication discourse CVE-2025-49845 Discourse users are able to see their own whispers even after being removed from a group that has been configured to… discourse CVE-2025-48954 Discourse vulnerable to XSS via user-provided query parameter in oauth failure flow discourse CVE-2025-48877 Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe discourse CVE-2025-48062 Discourse vulnerable to HTML injection when inviting to topic via email discourse CVE-2025-48053 Discourse vulnerable to DoS via large URL payload in PM to a bot discourse CVE-2025-47288 Discourse Policy plugin private group members visible discourse-policy CVE-2025-46824 Discourse Code Review Plugin vulnerable to XSS via auto link commits discourse-code-review CVE-2025-46813 Private data leak on login-required Discourse sites discourse CVE-2025-32376 Discourse DM limits aren’t always properly enforced discourse CVE-2025-24972 Discourse may bypass user preference when adding users to chat groups discourse CVE-2025-24808 Discourse has race condition when adding users to a group DM discourse CVE-2025-23023 Anonymous cache poisoning via request headers in Discourse discourse CVE-2025-22602 Stored DOM-based XSS (without CSP) via video placeholders in Discourse discourse CVE-2025-22601 Client Side Path Traversal using activate account route in Discourse discourse CVE-2024-56328 HTMLi(XSS without CSP) via Onebox urls in Discourse discourse CVE-2024-56197 Users can see other user's tagged PMs in Discourse discourse CVE-2024-55948 Anonymous cache poisoning via XHR requests in Discourse discourse CVE-2024-54142 Cross-site Scripting via Discourse-ai SharedAiConversation onebox in Discourse discourse-ai CVE-2024-53994 Potential bypass of chat permissions in Discourse discourse CVE-2024-53991 Potential Backup file leaked via Nginx in Discourse discourse CVE-2024-53851 Partial denial of service via inline oneboxes in Discourse discourse CVE-2024-53266 Cross-site Scripting (XSS) via topic titles when CSP disabled in Discourse discourse CVE-2024-52794 Magnific lightbox susceptible to Cross-site Scripting in Discourse discourse CVE-2024-52589 Moderators can view Screened emails even when the “moderators view emails” option is disabled in Discourse discourse CVE-2024-49765 Bypass of Discourse Connect using other login paths if enabled in Discourse discourse CVE-2024-47773 Anonymous cache poisoning via XHR requests in Discourse discourse CVE-2024-47772 Cross-site Scripting (XSS) via chat excerpts when content security policy (CSP) disabled in Discourse discourse CVE-2024-45303 Discourse Calendar plugin event names susceptible to XSS discourse-calendar CVE-2024-45297 Prevent topic list filtering by hidden tags for unauthorized users in Discourse discourse CVE-2024-45051 Bypass of email address validation via encoded email addresses in Discourse discourse CVE-2024-43789 Denial of service by the absence of restrictions on replies to posts in Discourse discourse CVE-2024-43408 Discourse Placeholder Forms has a XSS stopped by CSP discourse-placeholder-theme-component CVE-2024-39320 Discourse allows iframe injection though default site setting discourse CVE-2024-38360 Denial of service via Watched Words in Discourse discourse CVE-2024-37157 Discourse vulnerable to Server-Side Request Forgery via FastImage discourse CVE-2024-36122 Discourse doesn't limit reviewable user serializer payload discourse CVE-2024-36113 Discourse missing authorization checks for suspending admins/moderators discourse CVE-2024-35234 Discourse vulnerable to stored-dom XSS via Facebook Oneboxes discourse CVE-2024-35168 WordPress WP Discourse plugin <= 2.5.1 - Broken Access Control vulnerability Discourse CVE-2024-31219 Discourse-reactions' reaction data and public topic whisper content exposed on reactions given user activity page discourse-reactions CVE-2024-28242 Disclosure of the existence of secret categories with custom backgrounds in Discourse discourse CVE-2024-27100 Denial of service via Staff Actions in Discourse discourse CVE-2024-26145 Uninvited user is able to join and mark the attendance of the the private event discourse-calendar CVE-2024-24827 No rate limits on POST /uploads endpoint in Discourse discourse CVE-2024-24817 User can see invitees in events created in PMs and private categories discourse-calendar CVE-2024-24755 discourse-group-membership-ip-block is exposing potentially sensitive custom fields discourse-group-membership-ip-block CVE-2024-24748 Disclosure of the existence of secret subcategories in Discourse discourse CVE-2024-23834 Discourse improperly sanitized user input leads to XSS discourse CVE-2024-23654 discourse-ai admin-initiated SSRF when interacting with AI services discourse-ai CVE-2024-21658 Insufficient control of region value length in discourse-calendar discourse-calendar CVE-2024-21655 Insufficient control of custom field value sizes discourse CVE-2023-49099 Discourse secure uploads accessible to guests even when login is required discourse CVE-2023-49098 Reaction data for user notifications exposed in Discourse-reactions discourse-reactions CVE-2023-48297 Discourse vulnerable to unlimited mentioned users in message serializer discourse CVE-2023-46241 Potential account take over due to unverified emails from Microsoft Identity Platform discourse-microsoft-auth CVE-2023-46130 Bypassing height value allowed in some theme components discourse CVE-2023-45816 Unread bookmark reminder notifications that the user cannot access can be seen discourse CVE-2023-45806 Discourse vulnerable to DoS via Regexp Injection in Full Name discourse CVE-2023-45147 Arbitrary keys can be added to a topic's custom fields by any user in Discourse discourse CVE-2023-45131 Unauthenticated access to new private chat messages in Discourse discourse CVE-2023-44391 Prevent unauthorized access to summary details in Discourse discourse CVE-2023-44388 Malicious requests can fill up the log files resulting in a deinal of service in Discourse discourse CVE-2023-44384 Discourse-Jira could make SSRF attack by setting Jira URL to an arbitrary location discourse-jira 200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.