Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72730 | 8.7 HIGH | Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor |
| CVE-2026-72731 | 7.1 HIGH | Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explor |
| CVE-2026-72726 | 6.5 MEDIUM | Discourse: Unauthorized eavesdropping on private AI bot conversations. |
| CVE-2026-72720 | 6.4 MEDIUM | Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing |
| CVE-2026-72728 | 6.3 MEDIUM | Discourse: Onebox iframe origin allowlist enforces URL authority boundary |
| CVE-2026-72725 | 5.4 MEDIUM | Discourse: Stored XSS in staff action logs injects staff UI |
| CVE-2026-72721 | 5.3 MEDIUM | Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison |
| CVE-2026-72727 | 4.8 MEDIUM | Discourse: Stored XSS in the moderation review queue |
| CVE-2026-72722 | 4.3 MEDIUM | Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs |
| CVE-2026-72724 | 4.3 MEDIUM | Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismat |
| CVE-2026-72732 | 4.3 MEDIUM | Discourse: Templates endpoint exposes hidden tag names |
| CVE-2026-72729 | 2.0 LOW | Discourse: Stored XSS in discourse-local-dates plugin |
No comments yet