Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 259

All 259 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with the Discourse platform, focusing on the Common Weakness Enumeration classification tags managed by vendor Discourse. It aggregates a comprehensive list of identified security flaws, including buffer overflows, injection flaws, and cross-site scripting issues, covering reports published from early 2013 through the current year. Users can utilize this resource to track vendor security advisories over time, gain a deeper understanding of specific weakness classes affecting open-source forum software, and look up the historical vulnerability record for this specific product. The data is structured to help developers and system administrators assess the impact of known issues, review patch notes, and prioritize remediation efforts based on severity and exploitability. By centralizing this information, the page serves as a reference for understanding the security posture of Discourse instances and facilitates informed decision-making regarding software updates and configuration hardening. This approach supports transparency in open-source security by providing accessible historical context for past incidents and current risks without requiring users to navigate multiple external documentation sources. The aggregated data reflects reported vulnerabilities that have been publicly disclosed and assigned unique identifiers, ensuring traceability and reference for security professionals auditing their deployment environments against known threat models.

Vendor: discourse

CVE IDTitleCVSSSeverityPublished
CVE-2026-45780 Discourse: Private event sample invitees are serialized to non-invited event viewers CWE-200 5.3 Medium2026-07-09
CVE-2026-53963 Discourse: Stored-XSS in 2FA delete confirmation modal CWE-79 7.3 High2026-07-09
CVE-2026-59828 Discourse: Hidden post revisions leak through adjacent visible diffs CWE-200 5.3 Medium2026-07-09
CVE-2026-44787 Discourse: Signup-time primary_group_id assignment grants whisperer access CWE-269 8.2 High2026-07-09
CVE-2026-53962 Discourse: Insufficient SVG sanitization logic CWE-79 5.4 Medium2026-07-09
CVE-2026-55424 Discourse: Topic featured link susceptible to stored XSS CWE-79--2026-07-09
CVE-2026-45788 Discourse: Secure uploads exposed by hotlinked image copying CWE-200--2026-07-09
CVE-2026-49256 Discourse: Hidden tag names leaked via category serializers CWE-200--2026-07-09
CVE-2026-46413 Discourse: Regular users can route multipart uploads into the admin backup store CWE-862 6.5 Medium2026-07-09
CVE-2026-53961 Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding) CWE-345 6.5 Medium2026-07-09
CVE-2026-55420 Discourse: Remote code execution via pdf uploads CWE-78 7.5 High2026-07-09
CVE-2026-47264 Discourse: Don't leak restricted tag group names via tag info CWE-200 5.3 Medium2026-06-12
CVE-2026-47263 Discourse: Prevent webhook payload disclosure on event redelivery CWE-200 4.3 Medium2026-06-12
CVE-2026-45775 Discourse: Cross-site backup access via path traversal in multisite local backups CWE-22 6.8 Medium2026-06-12
CVE-2026-45085 Discourse: Chat misauthorization and information disclosure CWE-862 5.3 Medium2026-06-12
CVE-2026-44785 Discourse: Hidden reply-to post raw can be disclosed through AI explain prompts CWE-200 4.3 Medium2026-06-12
CVE-2026-44784 Discourse: Non-staff group owners can see email password in plaintext through group history CWE-200 6.5 Medium2026-06-12
CVE-2026-44783 Discourse: Replying to a whisper lets non-whisperers create staff-only whisper posts CWE-284 5.4 Medium2026-06-12
CVE-2026-44782 Discourse: GroupPostSerializer leaks hidden full names through reaction post association CWE-200 4.3 Medium2026-06-12
CVE-2026-44780 Discourse: Category queue reviewers can read raw incoming emails from queued posts CWE-200 4.3 Medium2026-06-12
CVE-2026-44779 Discourse: Bot debug endpoints disclose whisper translation audit logs CWE-200 4.3 Medium2026-06-12
CVE-2026-44786 Discourse: Public chat MessageBus broadcasts are not restricted to chat-eligible users CWE-200 7.5 High2026-06-12
CVE-2026-34154 Discourse has a subscription access bypass in its discourse-subscriptions plugin CWE-862--2026-05-19
CVE-2026-33514 Discourse: Information Disclosure in Form Template API Due to Missing Authorization CWE-862--2026-05-19
CVE-2026-32244 Discourse: Cached outdated summaries can leak removed content CWE-524 5.3 Medium2026-05-19
CVE-2026-34947 Discourse: Staged user custom fields are exposed on public invite pages CWE-200 4.3AIMediumAI2026-04-03
CVE-2026-27481 Discourse: Hidden tag visibility bypass on tag routes CWE-200 5.3AIMediumAI2026-04-03
CVE-2026-33415 Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure CWE-284 2.7 -2026-03-31
CVE-2026-33300 Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint CWE-200 4.3 -2026-03-31
CVE-2026-33185 Discourse: Group SMTP test endpoint susceptible to SSRF CWE-918 4.3 -2026-03-31

All 259 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.