Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.

Vendor: discourse

CVE ID Title CVSS Severity Published
CVE-2026-53960 Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD CWE-862 5.3 Medium 2026-08-17
CVE-2026-55704 Discourse: Shared-draft titles and excerpts leak through group post serialization CWE-862 4.3 Medium 2026-08-17
CVE-2026-55674 Discourse: Cache poisoning/XSS via color scheme cookies CWE-79 9.3 Critical 2026-08-17
CVE-2026-59829 Discourse: Review queue exposes flag-related private message excerpts to category group moderators CWE-862 4.3 Medium 2026-08-17
CVE-2026-72732 Discourse: Templates endpoint exposes hidden tag names CWE-862 4.3 Medium 2026-08-10
CVE-2026-72731 Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer CWE-89 7.1 High 2026-08-10
CVE-2026-72730 Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor CWE-79 8.7 High 2026-08-10
CVE-2026-72729 Discourse: Stored XSS in discourse-local-dates plugin CWE-79 2.0 Low 2026-08-10
CVE-2026-72728 Discourse: Onebox iframe origin allowlist enforces URL authority boundary CWE-20 6.3 Medium 2026-08-10
CVE-2026-72727 Discourse: Stored XSS in the moderation review queue CWE-79 4.8 Medium 2026-08-10
CVE-2026-72726 Discourse: Unauthorized eavesdropping on private AI bot conversations. CWE-200 6.5 Medium 2026-08-10
CVE-2026-72725 Discourse: Stored XSS in staff action logs injects staff UI CWE-79 5.4 Medium 2026-08-10
CVE-2026-72724 Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch CWE-639 4.3 Medium 2026-08-10
CVE-2026-72723 Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tags CWE-862 5.3 Medium 2026-08-10
CVE-2026-72722 Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs CWE-862 4.3 Medium 2026-08-10
CVE-2026-72721 Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison CWE-178 5.3 Medium 2026-08-10
CVE-2026-72720 Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing CWE-79 6.4 Medium 2026-08-10
CVE-2026-45780 Discourse: Private event sample invitees are serialized to non-invited event viewers CWE-200 5.3 Medium 2026-07-09
CVE-2026-53963 Discourse: Stored-XSS in 2FA delete confirmation modal CWE-79 7.3 High 2026-07-09
CVE-2026-59828 Discourse: Hidden post revisions leak through adjacent visible diffs CWE-200 5.3 Medium 2026-07-09
CVE-2026-44787 Discourse: Signup-time primary_group_id assignment grants whisperer access CWE-269 8.2 High 2026-07-09
CVE-2026-53962 Discourse: Insufficient SVG sanitization logic CWE-79 5.4 Medium 2026-07-09
CVE-2026-55424 Discourse: Topic featured link susceptible to stored XSS CWE-79 - - 2026-07-09
CVE-2026-45788 Discourse: Secure uploads exposed by hotlinked image copying CWE-200 - - 2026-07-09
CVE-2026-49256 Discourse: Hidden tag names leaked via category serializers CWE-200 - - 2026-07-09
CVE-2026-46413 Discourse: Regular users can route multipart uploads into the admin backup store CWE-862 6.5 Medium 2026-07-09
CVE-2026-53961 Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding) CWE-345 6.5 Medium 2026-07-09
CVE-2026-55420 Discourse: Remote code execution via pdf uploads CWE-78 7.5 High 2026-07-09
CVE-2026-47264 Discourse: Don't leak restricted tag group names via tag info CWE-200 5.3 Medium 2026-06-12
CVE-2026-47263 Discourse: Prevent webhook payload disclosure on event redelivery CWE-200 4.3 Medium 2026-06-12

All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.