Discourse 是一个开源的讨论平台。在版本 2026.1.8、2026.6.3、2026.7.2 和 2026.8.0 之前,topic small-action(话题小操作)和 nested-activity-log(嵌套活动日志)组件会将自由格式的 action_code_who 值直接插值到 mention-link(提及链接)的 href 属性中,而未进行 URL 编码。一个包含引号的用户显示名称可以终止预期的 URL 属性,并将攻击者控制的元素注入到受信任的已渲染标记中。虽然可见的提及文本已被转义,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91122 | 8.7 HIGH | Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users |
| CVE-2026-91123 | 7.2 HIGH | Discourse: Reject literal backslash path separators in iframe src traversal guard |
| CVE-2026-91133 | 6.5 MEDIUM | Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure |
| CVE-2026-91134 | 5.4 MEDIUM | Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlis |
| CVE-2026-91120 | 5.4 MEDIUM | Discourse: Stored HTML injection in video notification emails |
| CVE-2026-91121 | 5.0 MEDIUM | Discourse: Chat upload filenames rendered as raw HTML in excerpts |
| CVE-2026-91132 | 4.3 MEDIUM | Discourse: Wildcard iframe origin allowlist bypass via authority separators |
| CVE-2026-84302 | 4.2 MEDIUM | Discourse: Non-participant moderators can read, edit, and delete PM content through Discou |
No comments yet