Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-26265 | 7.5 HIGH | Discourse has IDOR vulnerability in the directory items endpoint |
| CVE-2026-26078 | 7.5 HIGH | Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint |
| CVE-2026-26077 | 6.5 MEDIUM | Discourse doesn't ensure webhooks require a token |
| CVE-2026-26207 | 5.4 MEDIUM | DIscourse's discourse-policy plugin lacks post access check |
| CVE-2026-28227 | Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Tim | |
| CVE-2026-28219 | Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Bann | |
| CVE-2026-28218 | Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query | |
| CVE-2026-27154 | Discourse has XSS when editing a malicious post | |
| CVE-2026-27153 | Discourse doesn't prevent moderators from exporting user Chat DMs | |
| CVE-2026-27152 | DIscourse has DM communication-preference bypass when adding members | |
| CVE-2026-27162 | DIscourse doesn't prevent whispers to leak in excerpts | |
| CVE-2026-27151 | Discourse doesn't validate destination topic when moving posts | |
| CVE-2026-27150 | Discourse doesn't ensure guardian check when creating QueryGroupBookmark | |
| CVE-2026-27149 | Discourse has SQL injection in PM tag filtering | |
| CVE-2026-27021 | Discourse: Poll voters endpoint lacked post visibility checks | |
| CVE-2026-26979 | Discourse: TL4 users are able to change status of restricted topics |
No comments yet