Discourse是Discourse开源的一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2025.12.2之前版本、2026.1.1之前版本和2026.2.0之前版本存在安全漏洞,该漏洞源于目录项端点存在不安全的直接对象引用,可能导致任何用户(包括匿名用户)批量泄露所有用户的私有字段数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Discourse prior to 2025.12.2, 2026.1.1, and 2026.2.0 contains an IDOR vulnerability caused by lack of authorization checks on user_field_ids parameter in DirectoryItemsController#index, letting any user retrieve private user field values, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-26265.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-26078 | 7.5 HIGH | Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint |
| CVE-2026-26077 | 6.5 MEDIUM | Discourse doesn't ensure webhooks require a token |
| CVE-2026-26207 | 5.4 MEDIUM | DIscourse's discourse-policy plugin lacks post access check |
| CVE-2026-26973 | 4.3 MEDIUM | Discourse doesn't scope reviewable notes to user-visible reviewables |
| CVE-2026-28227 | Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Tim | |
| CVE-2026-28219 | Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Bann | |
| CVE-2026-28218 | Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query | |
| CVE-2026-27154 | Discourse has XSS when editing a malicious post | |
| CVE-2026-27153 | Discourse doesn't prevent moderators from exporting user Chat DMs | |
| CVE-2026-27152 | DIscourse has DM communication-preference bypass when adding members | |
| CVE-2026-27162 | DIscourse doesn't prevent whispers to leak in excerpts | |
| CVE-2026-27151 | Discourse doesn't validate destination topic when moving posts | |
| CVE-2026-27150 | Discourse doesn't ensure guardian check when creating QueryGroupBookmark | |
| CVE-2026-27149 | Discourse has SQL injection in PM tag filtering | |
| CVE-2026-27021 | Discourse: Poll voters endpoint lacked post visibility checks | |
| CVE-2026-26979 | Discourse: TL4 users are able to change status of restricted topics |
No comments yet