Discourse是Discourse开源的一套开源的社区讨论平台。该平台包括社区、电子邮件和聊天室等功能。 Discourse 2026.3.0-latest.1之前版本、2026.2.1之前版本和2026.1.2之前版本存在安全漏洞,该漏洞源于ComposerController#mentions端点处理不当,可能向任何可以给群组发消息的经过身份验证的用户泄露隐藏的群组成员身份。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33424 | 5.9 MEDIUM | PM access granted through invites after access revocation |
| CVE-2026-33411 | 5.4 MEDIUM | Discourse's solved topic stream has potential stored XSS in topic title |
| CVE-2026-33251 | 5.4 MEDIUM | Discourse has a Hidden Solved topics permission bypass |
| CVE-2026-31805 | 5.3 MEDIUM | Discourse has a poll authorization bypass via post_id array parameter |
| CVE-2026-33422 | 3.5 LOW | Discourse exposes ip_address of flagged user |
| CVE-2026-33426 | 3.5 LOW | Discourse users can edit or synonymize hidden tags they can't see |
| CVE-2026-30888 | 2.2 LOW | Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endp |
| CVE-2026-30889 | Discourse has Unauthorized Post Data Exposure in discourse-user-notes | |
| CVE-2026-30891 | Discourse hasUnauthorized Exposure of Private User Action Types | |
| CVE-2026-32114 | Discourse's unscoped status lookups leak restricted metadata | |
| CVE-2026-33291 | Discourse user can create Zendesk tickets even when it does not have access to topic | |
| CVE-2026-33423 | Discourse staff can modify any user's group notification level | |
| CVE-2026-33425 | Discourse has inferable private group membership or existence via exclude_groups parameter | |
| CVE-2026-33427 | Discourse Authorization Page Displays Unvalidated Redirect Domain | |
| CVE-2026-33428 | Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership |
No comments yet