Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 268 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-33425 Discourse has inferable private group membership or existence via exclude_groups parameter discoursediscourse 中危 -2026-03-20 23:12:30 Deep Dive
CVE-2026-33424 PM access granted through invites after access revocation discoursediscourse Medium 5.9 2026-03-20 23:08:12 Deep Dive
CVE-2026-33423 Discourse staff can modify any user's group notification level discoursediscourse 中危 -2026-03-20 23:06:22 Deep Dive
CVE-2026-33422 Discourse exposes ip_address of flagged user discoursediscourse Low 3.5 2026-03-20 23:04:45 Deep Dive
CVE-2026-33411 Discourse's solved topic stream has potential stored XSS in topic title discoursediscourse Medium 5.4 2026-03-20 22:58:15 Deep Dive
CVE-2026-33291 Discourse user can create Zendesk tickets even when it does not have access to topic discoursediscourse 中危 -2026-03-20 22:56:06 Deep Dive
CVE-2026-33251 Discourse has a Hidden Solved topics permission bypass discoursediscourse Medium 5.4 2026-03-20 22:52:37 Deep Dive
CVE-2026-32114 Discourse's unscoped status lookups leak restricted metadata discoursediscourse 中危 -2026-03-20 03:13:35 Deep Dive
CVE-2026-31869 Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check discoursediscourse 中危 -2026-03-20 03:10:43 Deep Dive
CVE-2026-31805 Discourse has a poll authorization bypass via post_id array parameter discoursediscourse Medium 5.3 2026-03-20 03:07:15 Deep Dive
CVE-2026-30891 Discourse hasUnauthorized Exposure of Private User Action Types discoursediscourse 中危 -2026-03-20 03:02:27 Deep Dive
CVE-2026-30889 Discourse has Unauthorized Post Data Exposure in discourse-user-notes discoursediscourse 中危 -2026-03-20 02:59:14 Deep Dive
CVE-2026-30888 Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpoint discoursediscourse Low 2.2 2026-03-20 02:55:58 Deep Dive
CVE-2026-33408 Discourse has Improper Authorization in "Post Edits" Report For Moderators discoursediscourse Low 2.2 2026-03-19 22:35:14 Deep Dive
CVE-2026-33395 Discourse has stored click‑based XSS via Graphviz SVG javascript: links discoursediscourse Medium 4.4 2026-03-19 22:33:19 Deep Dive
CVE-2026-33394 Discourse leaks PM post edits to moderators discoursediscourse Low 2.7 2026-03-19 22:06:07 Deep Dive
CVE-2026-33393 Discourse fixes loose hostname matching in spam host allowlist discoursediscourse Medium 4.3 2026-03-19 22:04:26 Deep Dive
CVE-2026-33355 Discourse filters whisper posts from private-posts feed discoursediscourse Medium 6.5 2026-03-19 22:01:42 Deep Dive
CVE-2026-33410 Discourse hardens chat DM channel creation and expansion discoursediscourse Medium 5.4 2026-03-19 21:57:27 Deep Dive
CVE-2026-32099 Discourse prevents hidden profile data leak via user onebox discoursediscourse Medium 4.3 2026-03-19 21:52:25 Deep Dive