vciy

CVEs we hold for Discourse

Records whose assigning authority named Discourse as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-72732Discourse: Templates endpoint exposes hidden tag namesdiscourse
CVE-2026-72731Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorerdiscourse
CVE-2026-72730Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editordiscourse
CVE-2026-72729Discourse: Stored XSS in discourse-local-dates plugindiscourse
CVE-2026-72728Discourse: Onebox iframe origin allowlist enforces URL authority boundarydiscourse
CVE-2026-72727Discourse: Stored XSS in the moderation review queuediscourse
CVE-2026-72726Discourse: Unauthorized eavesdropping on private AI bot conversations.discourse
CVE-2026-72725Discourse: Stored XSS in staff action logs injects staff UIdiscourse
CVE-2026-72724Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatchdiscourse
CVE-2026-72723Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tagsdiscourse
CVE-2026-72722Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLsdiscourse
CVE-2026-72721Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparisondiscourse
CVE-2026-72720Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsingdiscourse
CVE-2026-59829Discourse: Review queue exposes flag-related private message excerpts to category group moderatorsdiscourse
CVE-2026-59828Discourse: Hidden post revisions leak through adjacent visible diffsdiscourse
CVE-2026-55704Discourse: Shared-draft titles and excerpts leak through group post serializationdiscourse
CVE-2026-55674Discourse: Cache poisoning/XSS via color scheme cookiesdiscourse
CVE-2026-55424Discourse: Topic featured link susceptible to stored XSSdiscourse
CVE-2026-55420Discourse: Remote code execution via pdf uploadsdiscourse
CVE-2026-53963Discourse: Stored-XSS in 2FA delete confirmation modaldiscourse
CVE-2026-53962Discourse: Insufficient SVG sanitization logicdiscourse
CVE-2026-53961Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)discourse
CVE-2026-53960Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LDdiscourse
CVE-2026-49256Discourse: Hidden tag names leaked via category serializersdiscourse
CVE-2026-47264Discourse: Don't leak restricted tag group names via tag infodiscourse
CVE-2026-47263Discourse: Prevent webhook payload disclosure on event redeliverydiscourse
CVE-2026-46413Discourse: Regular users can route multipart uploads into the admin backup storediscourse
CVE-2026-45788Discourse: Secure uploads exposed by hotlinked image copyingdiscourse
CVE-2026-45780Discourse: Private event sample invitees are serialized to non-invited event viewersdiscourse
CVE-2026-45775Discourse: Cross-site backup access via path traversal in multisite local backupsdiscourse
CVE-2026-45085Discourse: Chat misauthorization and information disclosurediscourse
CVE-2026-44787Discourse: Signup-time primary_group_id assignment grants whisperer accessdiscourse
CVE-2026-44786Discourse: Public chat MessageBus broadcasts are not restricted to chat-eligible usersdiscourse
CVE-2026-44785Discourse: Hidden reply-to post raw can be disclosed through AI explain promptsdiscourse
CVE-2026-44784Discourse: Non-staff group owners can see email password in plaintext through group historydiscourse
CVE-2026-44783Discourse: Replying to a whisper lets non-whisperers create staff-only whisper postsdiscourse
CVE-2026-44782Discourse: GroupPostSerializer leaks hidden full names through reaction post associationdiscourse
CVE-2026-44780Discourse: Category queue reviewers can read raw incoming emails from queued postsdiscourse
CVE-2026-44779Discourse: Bot debug endpoints disclose whisper translation audit logsdiscourse
CVE-2026-34947Discourse: Staged user custom fields are exposed on public invite pagesdiscourse
CVE-2026-34154Discourse has a subscription access bypass in its discourse-subscriptions plugindiscourse
CVE-2026-33514Discourse: Information Disclosure in Form Template API Due to Missing Authorizationdiscourse
CVE-2026-33428Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membershipdiscourse
CVE-2026-33427Discourse Authorization Page Displays Unvalidated Redirect Domaindiscourse
CVE-2026-33426Discourse users can edit or synonymize hidden tags they can't seediscourse
CVE-2026-33425Discourse has inferable private group membership or existence via exclude_groups parameterdiscourse
CVE-2026-33424PM access granted through invites after access revocationdiscourse
CVE-2026-33423Discourse staff can modify any user's group notification leveldiscourse
CVE-2026-33422Discourse exposes ip_address of flagged userdiscourse
CVE-2026-33415Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposurediscourse
CVE-2026-33411Discourse's solved topic stream has potential stored XSS in topic titlediscourse
CVE-2026-33410Discourse hardens chat DM channel creation and expansiondiscourse
CVE-2026-33408Discourse has Improper Authorization in "Post Edits" Report For Moderatorsdiscourse
CVE-2026-33395Discourse has stored click‑based XSS via Graphviz SVG javascript: linksdiscourse
CVE-2026-33394Discourse leaks PM post edits to moderatorsdiscourse
CVE-2026-33393Discourse fixes loose hostname matching in spam host allowlistdiscourse
CVE-2026-33355Discourse filters whisper posts from private-posts feeddiscourse
CVE-2026-33300Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpointdiscourse
CVE-2026-33291Discourse user can create Zendesk tickets even when it does not have access to topicdiscourse
CVE-2026-33251Discourse has a Hidden Solved topics permission bypassdiscourse
CVE-2026-33185Discourse: Group SMTP test endpoint susceptible to SSRFdiscourse
CVE-2026-33074Discourse: Vulnerability in discourse-subscriptions plugin allowing users to self-grant to higher tier subscriptionsdiscourse
CVE-2026-33073discourse-subscriptions plugin leaking stripe API key in multisite environmentdiscourse
CVE-2026-32951Discourse: Authorization bypass in oneboxer via user-controlled category iddiscourse
CVE-2026-32620Discourse: Missing post-level authorization allows whisper metadata disclosurediscourse
CVE-2026-32619Discourse: Insufficient topic visibility check allows unauthorized poll manipulation in private categoriesdiscourse
CVE-2026-32618Discourse: Unauthorized channel membership inference via excluded_memberships_channel_iddiscourse
CVE-2026-32615Discourse: Category group moderators can perform actions on topics in restricted categories without read accessdiscourse
CVE-2026-32607Discourse: Stored XSS via unescaped assignee namediscourse
CVE-2026-32273Discourse: XSS on category description update via APIdiscourse
CVE-2026-32244Discourse: Cached outdated summaries can leak removed contentdiscourse
CVE-2026-32243Discourse: Stored XSS in discourse-ai shared conversations oneboxdiscourse
CVE-2026-32143Discourse: Admin-only report can be exported by moderatorsdiscourse
CVE-2026-32114Discourse's unscoped status lookups leak restricted metadatadiscourse
CVE-2026-32113Discourse: Open redirect via `sso_destination_url` cookie in `enter`discourse
CVE-2026-32099Discourse prevents hidden profile data leak via user oneboxdiscourse
CVE-2026-31869Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` checkdiscourse
CVE-2026-31805Discourse has a poll authorization bypass via post_id array parameterdiscourse
CVE-2026-30891Discourse hasUnauthorized Exposure of Private User Action Typesdiscourse
CVE-2026-30889Discourse has Unauthorized Post Data Exposure in discourse-user-notesdiscourse
CVE-2026-30888Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpointdiscourse
CVE-2026-29072Discourse missing permission check for policy creation in discourse-policydiscourse
CVE-2026-28282Discourse vulnerable to group membership addition permission bypass via discourse-policy plugindiscourse
CVE-2026-28227Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Timer publish_to_categorydiscourse
CVE-2026-28219Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Bannersdiscourse
CVE-2026-28218Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Executiondiscourse
CVE-2026-27936Discourse discloses restricted post-action counts to non-privileged usersdiscourse
CVE-2026-27935Discourse leaks private topic metadata to non-authorized usersdiscourse
CVE-2026-27934Discourse leaks private topic title and post excerpt via user action API endpointdiscourse
CVE-2026-27740Discourse has Stored XSS in AI Triage Automationdiscourse
CVE-2026-27570Discourse Vulnerable to Stored XSS via Shared AI Conversation Oneboxdiscourse
CVE-2026-27491Discourse has a bypass of official warnings messages by non-staff usersdiscourse
CVE-2026-27481Discourse: Hidden tag visibility bypass on tag routesdiscourse
CVE-2026-27454Discourse has check revision visibility on posts endpointdiscourse
CVE-2026-27166Discourse vulnerable to HTML injection via prohibited iframe URLsdiscourse
CVE-2026-27162DIscourse doesn't prevent whispers to leak in excerptsdiscourse
CVE-2026-27154Discourse has XSS when editing a malicious postdiscourse
CVE-2026-27153Discourse doesn't prevent moderators from exporting user Chat DMsdiscourse
CVE-2026-27152DIscourse has DM communication-preference bypass when adding membersdiscourse
CVE-2026-27151Discourse doesn't validate destination topic when moving postsdiscourse
CVE-2026-27150Discourse doesn't ensure guardian check when creating QueryGroupBookmarkdiscourse
CVE-2026-27149Discourse has SQL injection in PM tag filteringdiscourse
CVE-2026-27021Discourse: Poll voters endpoint lacked post visibility checksdiscourse
CVE-2026-26979Discourse: TL4 users are able to change status of restricted topicsdiscourse
CVE-2026-26973Discourse doesn't scope reviewable notes to user-visible reviewablesdiscourse
CVE-2026-26265Discourse has IDOR vulnerability in the directory items endpointdiscourse
CVE-2026-26207DIscourse's discourse-policy plugin lacks post access checkdiscourse
CVE-2026-26078Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpointdiscourse
CVE-2026-26077Discourse doesn't ensure webhooks require a tokendiscourse
CVE-2026-24742Discourse staff action logs expose sensitive information to moderatorsdiscourse
CVE-2026-23743Discourse allows permalinks to restricted resources to leak resource slugs to unauthorized usersdiscourse
CVE-2026-21865Discourse topic conversion permission vulnerability for moderatorsdiscourse
CVE-2025-69289Discourse has insecure default configuration that allows non-admin moderators to takeover any non-staff account via…discourse
CVE-2025-69218Discourse moderators can access admin-only reports exposing private upload URLsdiscourse
CVE-2025-68934Discourse Has Denial of Service (DoS) Vulnerability in Drafts Creation Endpointdiscourse
CVE-2025-68933Discourse non-admin moderators can exfiltrate private content via post ownership transferdiscourse
CVE-2025-68666Discourse users archives leaked to users with moderation privilegesdiscourse
CVE-2025-68662FinalDestination hostname matching allows SSRF protection bypassdiscourse
CVE-2025-68660Discourse AI Discover's continue conversation allows threat actor to impersonate userdiscourse
CVE-2025-68659Discourse has DoS vulnerability in username change endpointdiscourse
CVE-2025-68479Discourse subscriptions are susceptible to takeoverdiscourse
CVE-2025-67723Discourse vulnerable to stored Cross-site Scripting via Katex in discourse-math plugindiscourse
CVE-2025-66488Discourse allows script execution in uploaded HTML/XML files on S3discourse
CVE-2025-64528Users are able to find users by name even when `enable_names` is offdiscourse
CVE-2025-61598Discourse is missing Cache-Control response header on error responsesdiscourse
CVE-2025-59337Discourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite Deploymentsdiscourse
CVE-2025-58055Discourse AI Suggestions Contain Insecure Direct Object Referencediscourse
CVE-2025-58054Discourse is vulnerable to XSS when quoting chat messagesdiscourse
CVE-2025-54411Discourse welcome banner user name XSSdiscourse
CVE-2025-53102Discourse's WebAuthn challenge isn't cleared from user session after authenticationdiscourse
CVE-2025-49845Discourse users are able to see their own whispers even after being removed from a group that has been configured to…discourse
CVE-2025-48954Discourse vulnerable to XSS via user-provided query parameter in oauth failure flowdiscourse
CVE-2025-48877Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframediscourse
CVE-2025-48062Discourse vulnerable to HTML injection when inviting to topic via emaildiscourse
CVE-2025-48053Discourse vulnerable to DoS via large URL payload in PM to a botdiscourse
CVE-2025-47288Discourse Policy plugin private group members visiblediscourse-policy
CVE-2025-46824Discourse Code Review Plugin vulnerable to XSS via auto link commitsdiscourse-code-review
CVE-2025-46813Private data leak on login-required Discourse sitesdiscourse
CVE-2025-32376Discourse DM limits aren’t always properly enforceddiscourse
CVE-2025-24972Discourse may bypass user preference when adding users to chat groupsdiscourse
CVE-2025-24808Discourse has race condition when adding users to a group DMdiscourse
CVE-2025-23023Anonymous cache poisoning via request headers in Discoursediscourse
CVE-2025-22602Stored DOM-based XSS (without CSP) via video placeholders in Discoursediscourse
CVE-2025-22601Client Side Path Traversal using activate account route in Discoursediscourse
CVE-2024-56328HTMLi(XSS without CSP) via Onebox urls in Discoursediscourse
CVE-2024-56197Users can see other user's tagged PMs in Discoursediscourse
CVE-2024-55948Anonymous cache poisoning via XHR requests in Discoursediscourse
CVE-2024-54142Cross-site Scripting via Discourse-ai SharedAiConversation onebox in Discoursediscourse-ai
CVE-2024-53994Potential bypass of chat permissions in Discoursediscourse
CVE-2024-53991Potential Backup file leaked via Nginx in Discoursediscourse
CVE-2024-53851Partial denial of service via inline oneboxes in Discoursediscourse
CVE-2024-53266Cross-site Scripting (XSS) via topic titles when CSP disabled in Discoursediscourse
CVE-2024-52794Magnific lightbox susceptible to Cross-site Scripting in Discoursediscourse
CVE-2024-52589Moderators can view Screened emails even when the “moderators view emails” option is disabled in Discoursediscourse
CVE-2024-49765Bypass of Discourse Connect using other login paths if enabled in Discoursediscourse
CVE-2024-47773Anonymous cache poisoning via XHR requests in Discoursediscourse
CVE-2024-47772Cross-site Scripting (XSS) via chat excerpts when content security policy (CSP) disabled in Discoursediscourse
CVE-2024-45303Discourse Calendar plugin event names susceptible to XSSdiscourse-calendar
CVE-2024-45297Prevent topic list filtering by hidden tags for unauthorized users in Discoursediscourse
CVE-2024-45051Bypass of email address validation via encoded email addresses in Discoursediscourse
CVE-2024-43789Denial of service by the absence of restrictions on replies to posts in Discoursediscourse
CVE-2024-43408Discourse Placeholder Forms has a XSS stopped by CSPdiscourse-placeholder-theme-component
CVE-2024-39320Discourse allows iframe injection though default site settingdiscourse
CVE-2024-38360Denial of service via Watched Words in Discoursediscourse
CVE-2024-37299Discourse vulnerable to DoS via Tag Groupdiscourse
CVE-2024-37165Discourse has an XSS via Onebox systemdiscourse
CVE-2024-37157Discourse vulnerable to Server-Side Request Forgery via FastImagediscourse
CVE-2024-36122Discourse doesn't limit reviewable user serializer payloaddiscourse
CVE-2024-36113Discourse missing authorization checks for suspending admins/moderatorsdiscourse
CVE-2024-35234Discourse vulnerable to stored-dom XSS via Facebook Oneboxesdiscourse
CVE-2024-35227Discourse vulnerable to DoS through Oneboxdiscourse
CVE-2024-35168WordPress WP Discourse plugin <= 2.5.1 - Broken Access Control vulnerabilityDiscourse
CVE-2024-31219Discourse-reactions' reaction data and public topic whisper content exposed on reactions given user activity pagediscourse-reactions
CVE-2024-28242Disclosure of the existence of secret categories with custom backgrounds in Discoursediscourse
CVE-2024-27100Denial of service via Staff Actions in Discoursediscourse
CVE-2024-27085Denial of service through invites in Discoursediscourse
CVE-2024-26145Uninvited user is able to join and mark the attendance of the the private eventdiscourse-calendar
CVE-2024-24827No rate limits on POST /uploads endpoint in Discoursediscourse
CVE-2024-24817User can see invitees in events created in PMs and private categoriesdiscourse-calendar
CVE-2024-24755discourse-group-membership-ip-block is exposing potentially sensitive custom fieldsdiscourse-group-membership-ip-block
CVE-2024-24748Disclosure of the existence of secret subcategories in Discoursediscourse
CVE-2024-23834Discourse improperly sanitized user input leads to XSSdiscourse
CVE-2024-23654discourse-ai admin-initiated SSRF when interacting with AI servicesdiscourse-ai
CVE-2024-21658Insufficient control of region value length in discourse-calendardiscourse-calendar
CVE-2024-21655Insufficient control of custom field value sizesdiscourse
CVE-2023-49099Discourse secure uploads accessible to guests even when login is requireddiscourse
CVE-2023-49098Reaction data for user notifications exposed in Discourse-reactionsdiscourse-reactions
CVE-2023-48297Discourse vulnerable to unlimited mentioned users in message serializerdiscourse
CVE-2023-47121Discourse SSRF vulnerability in Embeddingdiscourse
CVE-2023-47120Discourse DoS through Onebox favicon URLdiscourse
CVE-2023-47119HTML injection in oneboxed linksdiscourse
CVE-2023-46241Potential account take over due to unverified emails from Microsoft Identity Platformdiscourse-microsoft-auth
CVE-2023-46130Bypassing height value allowed in some theme componentsdiscourse
CVE-2023-45816Unread bookmark reminder notifications that the user cannot access can be seendiscourse
CVE-2023-45806Discourse vulnerable to DoS via Regexp Injection in Full Namediscourse
CVE-2023-45147Arbitrary keys can be added to a topic's custom fields by any user in Discoursediscourse
CVE-2023-45131Unauthenticated access to new private chat messages in Discoursediscourse
CVE-2023-44391Prevent unauthorized access to summary details in Discoursediscourse
CVE-2023-44388Malicious requests can fill up the log files resulting in a deinal of service in Discoursediscourse
CVE-2023-44384Discourse-Jira could make SSRF attack by setting Jira URL to an arbitrary locationdiscourse-jira

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.