Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.

Vendor: discourse

CVE ID Title CVSS Severity Published
CVE-2026-33427 Discourse Authorization Page Displays Unvalidated Redirect Domain CWE-862 4.3 - 2026-03-20
CVE-2026-33426 Discourse users can edit or synonymize hidden tags they can't see CWE-862 3.5 Low 2026-03-20
CVE-2026-33425 Discourse has inferable private group membership or existence via exclude_groups parameter CWE-203 5.3 - 2026-03-20
CVE-2026-33424 PM access granted through invites after access revocation CWE-863 5.9 Medium 2026-03-20
CVE-2026-33423 Discourse staff can modify any user's group notification level CWE-862 4.3 - 2026-03-20
CVE-2026-33422 Discourse exposes ip_address of flagged user CWE-200 3.5 Low 2026-03-20
CVE-2026-33411 Discourse's solved topic stream has potential stored XSS in topic title CWE-79 5.4 Medium 2026-03-20
CVE-2026-33291 Discourse user can create Zendesk tickets even when it does not have access to topic CWE-863 4.3 - 2026-03-20
CVE-2026-33251 Discourse has a Hidden Solved topics permission bypass CWE-863 5.4 Medium 2026-03-20
CVE-2026-32114 Discourse's unscoped status lookups leak restricted metadata CWE-639 4.3 - 2026-03-20
CVE-2026-31869 Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check CWE-200 4.3 - 2026-03-20
CVE-2026-31805 Discourse has a poll authorization bypass via post_id array parameter CWE-863 5.3 Medium 2026-03-20
CVE-2026-30891 Discourse hasUnauthorized Exposure of Private User Action Types CWE-200 6.5 - 2026-03-20
CVE-2026-30889 Discourse has Unauthorized Post Data Exposure in discourse-user-notes CWE-862 4.3 - 2026-03-20
CVE-2026-30888 Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpoint CWE-269 2.2 Low 2026-03-20
CVE-2026-33408 Discourse has Improper Authorization in "Post Edits" Report For Moderators CWE-862 2.2 Low 2026-03-19
CVE-2026-33395 Discourse has stored click‑based XSS via Graphviz SVG javascript: links CWE-79 4.4 Medium 2026-03-19
CVE-2026-33394 Discourse leaks PM post edits to moderators CWE-200 2.7 Low 2026-03-19
CVE-2026-33393 Discourse fixes loose hostname matching in spam host allowlist CWE-284 4.3 Medium 2026-03-19
CVE-2026-33355 Discourse filters whisper posts from private-posts feed CWE-200 6.5 Medium 2026-03-19
CVE-2026-33410 Discourse hardens chat DM channel creation and expansion CWE-863 5.4 Medium 2026-03-19
CVE-2026-32099 Discourse prevents hidden profile data leak via user onebox CWE-200 4.3 Medium 2026-03-19
CVE-2026-29072 Discourse missing permission check for policy creation in discourse-policy CWE-862 4.3 - 2026-03-19
CVE-2026-28282 Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin CWE-863 6.5 - 2026-03-19
CVE-2026-27936 Discourse discloses restricted post-action counts to non-privileged users CWE-863 4.3 - 2026-03-19
CVE-2026-27935 Discourse leaks private topic metadata to non-authorized users CWE-201 4.3 - 2026-03-19
CVE-2026-27934 Discourse leaks private topic title and post excerpt via user action API endpoint CWE-201 4.3 - 2026-03-19
CVE-2026-27740 Discourse has Stored XSS in AI Triage Automation CWE-79 5.4 - 2026-03-19
CVE-2026-27570 Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox CWE-79 5.4 - 2026-03-19
CVE-2026-27491 Discourse has a bypass of official warnings messages by non-staff users CWE-862 4.3 - 2026-03-19

All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.