Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

discourse — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in discourse, with AI-generated Chinese analysis, references, and POCs.

This page serves as a centralized vulnerability aggregation resource for the open-source discussion platform Discourse, focusing on Common Weakness Enumerations associated with this specific software vendor. It collects a comprehensive range of security defects, including cross-site scripting, unauthorized access, and code injection flaws, covering historical data from the product’s initial releases through to recent patches issued in 2024. By organizing these entries systematically, the page allows security researchers and administrators to effectively track the vendor’s security advisories, gain a deeper understanding of prevalent weakness classes affecting web-based forum applications, and examine the detailed vulnerability history of the Discourse ecosystem to assess long-term risk exposure and remediation trends. This structured approach facilitates proactive threat modeling and informs timely update strategies for deployed instances, ensuring that operators can identify patterns in defect types and prioritize fixes based on severity and exploitability rather than reacting to isolated incidents. The content is strictly informational and derived from public security disclosures, providing a neutral reference for auditing compliance and maintaining system integrity across diverse community hosting environments without implying endorsement or minimizing the severity of reported issues.

Vendor: discourse

CVE ID Title CVSS Severity Published
CVE-2026-27454 Discourse has check revision visibility on posts endpoint CWE-862 5.3 Medium 2026-03-19
CVE-2026-27166 Discourse vulnerable to HTML injection via prohibited iframe URLs CWE-80 4.1 Medium 2026-03-19
CVE-2026-28227 Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Timer publish_to_category CWE-863 4.3AI Medium AI 2026-02-26
CVE-2026-28219 Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Banners CWE-915 4.3AI Medium AI 2026-02-26
CVE-2026-28218 Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution CWE-284 8.8AI High AI 2026-02-26
CVE-2026-27154 Discourse has XSS when editing a malicious post CWE-79 5.4AI Medium AI 2026-02-26
CVE-2026-27153 Discourse doesn't prevent moderators from exporting user Chat DMs CWE-863 5.4AI Medium AI 2026-02-26
CVE-2026-27152 DIscourse has DM communication-preference bypass when adding members CWE-284 4.3AI Medium AI 2026-02-26
CVE-2026-27162 DIscourse doesn't prevent whispers to leak in excerpts CWE-200 4.3AI Medium AI 2026-02-26
CVE-2026-27151 Discourse doesn't validate destination topic when moving posts CWE-862 4.3AI Medium AI 2026-02-26
CVE-2026-27150 Discourse doesn't ensure guardian check when creating QueryGroupBookmark CWE-862 4.3AI Medium AI 2026-02-26
CVE-2026-27149 Discourse has SQL injection in PM tag filtering CWE-89 6.5AI Medium AI 2026-02-26
CVE-2026-27021 Discourse: Poll voters endpoint lacked post visibility checks CWE-862 5.3AI Medium AI 2026-02-26
CVE-2026-26979 Discourse: TL4 users are able to change status of restricted topics CWE-862 5.4AI Medium AI 2026-02-26
CVE-2026-26973 Discourse doesn't scope reviewable notes to user-visible reviewables CWE-863 4.3 Medium 2026-02-26
CVE-2026-26265 Discourse has IDOR vulnerability in the directory items endpoint CWE-863 7.5 High 2026-02-26
CVE-2026-26207 DIscourse's discourse-policy plugin lacks post access check CWE-862 5.4 Medium 2026-02-26
CVE-2026-26078 Discourse has authentication bypass vulnerability in the Patreon plugin webhook endpoint CWE-639 7.5 High 2026-02-26
CVE-2026-26077 Discourse doesn't ensure webhooks require a token CWE-287 6.5 Medium 2026-02-26
CVE-2026-24742 Discourse staff action logs expose sensitive information to moderators CWE-863 6.5 Medium 2026-01-28
CVE-2026-23743 Discourse allows permalinks to restricted resources to leak resource slugs to unauthorized users CWE-200 5.4AI Medium AI 2026-01-28
CVE-2026-21865 Discourse topic conversion permission vulnerability for moderators CWE-862 6.5 Medium 2026-01-28
CVE-2025-69289 Discourse has insecure default configuration that allows non-admin moderators to takeover any non-staff account via email change CWE-863 8.8AI High AI 2026-01-28
CVE-2025-69218 Discourse moderators can access admin-only reports exposing private upload URLs CWE-863 6.5AI Medium AI 2026-01-28
CVE-2025-68934 Discourse Has Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint CWE-770 6.5 Medium 2026-01-28
CVE-2025-68933 Discourse non-admin moderators can exfiltrate private content via post ownership transfer CWE-863 6.9 Medium 2026-01-28
CVE-2025-68666 Discourse users archives leaked to users with moderation privileges CWE-863 4.3AI Medium AI 2026-01-28
CVE-2025-68662 FinalDestination hostname matching allows SSRF protection bypass CWE-918 7.6 High 2026-01-28
CVE-2025-68660 Discourse AI Discover's continue conversation allows threat actor to impersonate user CWE-863 5.4AI Medium AI 2026-01-28
CVE-2025-68659 Discourse has DoS vulnerability in username change endpoint CWE-770 4.3 Medium 2026-01-28

All 276 known CVE vulnerabilities affecting discourse with full Chinese analysis, references, and POCs where available.