Discourse是Discourse开源的一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2025.12.2之前版本、2026.1.1之前版本和2026.2.0之前版本存在跨站脚本漏洞,该漏洞源于特定设置下用户全名可能被评估为原始HTML,可能导致编辑恶意用户帖子时触发跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-26265 | 7.5 HIGH | Discourse has IDOR vulnerability in the directory items endpoint |
| CVE-2026-26078 | 7.5 HIGH | Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint |
| CVE-2026-26077 | 6.5 MEDIUM | Discourse doesn't ensure webhooks require a token |
| CVE-2026-26207 | 5.4 MEDIUM | DIscourse's discourse-policy plugin lacks post access check |
| CVE-2026-26973 | 4.3 MEDIUM | Discourse doesn't scope reviewable notes to user-visible reviewables |
| CVE-2026-28227 | Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Tim | |
| CVE-2026-28219 | Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Bann | |
| CVE-2026-28218 | Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query | |
| CVE-2026-27153 | Discourse doesn't prevent moderators from exporting user Chat DMs | |
| CVE-2026-27152 | DIscourse has DM communication-preference bypass when adding members | |
| CVE-2026-27162 | DIscourse doesn't prevent whispers to leak in excerpts | |
| CVE-2026-27151 | Discourse doesn't validate destination topic when moving posts | |
| CVE-2026-27150 | Discourse doesn't ensure guardian check when creating QueryGroupBookmark | |
| CVE-2026-27149 | Discourse has SQL injection in PM tag filtering | |
| CVE-2026-27021 | Discourse: Poll voters endpoint lacked post visibility checks | |
| CVE-2026-26979 | Discourse: TL4 users are able to change status of restricted topics |
No comments yet