PatchSiren

discourse CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM discourse CVE published 2026-08-17

CVE-2026-59829

CVE-2026-59829 is a medium-severity vulnerability affecting the Discourse open-source discussion platform. It allows category group moderators to access excerpts of private messages attached to flags, even if they are not participants in those messages. This issue is fixed in Discourse versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1. The vulnerability affects sites with category group moderation enabl [truncated]

MEDIUM discourse CVE published 2026-08-17

CVE-2026-55704

CVE-2026-55704 is an information disclosure vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users with permission to view a group's activity but not shared drafts could still access shared-draft entries through group posts and mentions. This could reveal unpublished draft material, including topic titles and post excerpts. The i [truncated]

CRITICAL discourse CVE published 2026-08-17

CVE-2026-55674

CVE-2026-55674 is a critical vulnerability in Discourse, an open-source discussion platform. An unauthenticated attacker can inject arbitrary HTML into a Discourse page by sending a crafted cookie request, allowing for arbitrary JavaScript execution in visitors' browsers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The vulnerability requires immediate attention from defende [truncated]

MEDIUM discourse CVE published 2026-08-17

CVE-2026-53960

Discourse platform vulnerability leaks hidden post content in QAPage JSON-LD structured data, exposing sensitive information to unauthenticated visitors and search engines. This issue requires immediate attention and remediation to prevent content exposure. The vulnerability affects Discourse installations prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Affected administrators and users with [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72732

CVE-2026-72732 is a vulnerability in the Discourse open-source discussion platform. The discourse_templates endpoint exposed hidden tag names due to a flawed serializer that did not filter tags through the request Guardian, allowing users to see tags they were not permitted to view. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

HIGH discourse CVE published 2026-08-10

CVE-2026-72731

CVE-2026-72731 is a high-severity vulnerability in the Discourse open-source discussion platform. Affected versions include 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1. The issue allows unauthorized SQL execution through the Data Explorer plugin, enabling any table to be read but not modified. This vulnerability has significant implications for Discourse administrators and us [truncated]

HIGH discourse CVE published 2026-08-10

CVE-2026-72730

CVE-2026-72730 is a high-severity vulnerability in the Discourse platform, an open-source discussion platform. The vulnerability allows for stored cross-site scripting (XSS) attacks due to the Rich Text Editor rendering chat-transcript usernames as HTML. This issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Affected deployments should prioritize upgrading to prevent potential XSS at [truncated]

LOW discourse CVE published 2026-08-10

CVE-2026-72729

CVE-2026-72729 is a vulnerability in the discourse-local-dates plugin for Discourse, an open-source discussion platform. The plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Defenders should assess exposure and update to a fixed version if necessary. The [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72728

CVE-2026-72728 is a medium-severity vulnerability in the Discourse open-source discussion platform. An authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. The issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1. This vulnerability allows attackers to inject malicious content, potentially leading to un [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72727

CVE-2026-72727 is a stored cross-site scripting (XSS) vulnerability in the Discourse open-source discussion platform. A low-privileged user could place crafted content in the moderation review queue that executed stored XSS when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72726

CVE-2026-72726 is a vulnerability in the Discourse open-source discussion platform that allows an authenticated user to eavesdrop on private AI bot conversations through the AI bot reply stream. The issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. This vulnerability impacts Discourse instances using AI bots, allowing unauthorized access to sensitive conversations. Defenders should a [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72725

CVE-2026-72725 is a medium-severity vulnerability in the Discourse open-source discussion platform. Prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the staff action log model rendered unescaped previous and new value fields, potentially allowing stored cross-site scripting (XSS) attacks in the staff interface. This vulnerability could allow attackers to inject malicious scripts into the staf [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72724

CVE-2026-72724 is a vulnerability in the Discourse open-source discussion platform that allows an authenticated user to obtain private thread message content by pairing a public channel ID with a private thread ID in a /onebox.json request. This issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The vulnerability exists due to inadequate access controls in the chat plugin, specificall [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72723

CVE-2026-72723 is a vulnerability in Discourse, an open-source discussion platform. The issue allows an unauthenticated user to retrieve restricted tag names and descriptions through /site.json when those tags are limited by inaccessible categories, category tag groups, or tag-group permissions. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72722

An authenticated user can submit links to restricted topics, private messages, or hidden posts and receive canonicalized slugs or titles in the composer_messages duplicate_lookup response even though the targets are not visible to that user. This issue affects Discourse, an open-source discussion platform, where TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not cons [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72721

CVE-2026-72721 is a medium-severity vulnerability in the Discourse platform that allows an attacker to bypass Onebox domain restrictions by manipulating hostname casing. This issue arises from the case-sensitive comparison of hostnames and blocked_onebox_domains entries in Onebox::DomainChecker.is_blocked?. The vulnerability was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Affected Discou [truncated]

MEDIUM discourse CVE published 2026-08-10

CVE-2026-72720

Discourse users should assess exposure and prioritize verification of Vimeo iframe and secure-upload URL handling. This involves reviewing the PrettyText.format_for_email feature, which has an HTML injection vulnerability. The vulnerability allows crafted Vimeo iframe sources, secure-upload URLs, or dimensions, and hashtag data-slug values to cause decoded attribute text to be reinterpreted as HTML. Affec [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-59828

CVE-2026-59828 is a medium-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue has been fixed in the mentioned versions. The vulnerability allows for the leakag [truncated]

HIGH discourse CVE published 2026-07-09

CVE-2026-55424

CVE-2026-55424 is a high-severity vulnerability in Discourse, a popular open-source discussion platform. The vulnerability allows a user with permission to set a featured link to inject JavaScript when default Content Security Policy protections are modified or disabled. This issue was fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability exists in the topic list feature of Disco [truncated]

HIGH discourse CVE published 2026-07-09

CVE-2026-53963

CVE-2026-53963 is a high-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. The vulnerability has a CVSS score of 7.3 and [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-53962

CVE-2026-53962 is a vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This vulnerability has a medium severity and could allow attackers to execute [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-53961

CVE-2026-53961 is a medium-severity vulnerability in Discourse's AWS SES bounce webhook. The issue allowed any AWS account holder to publish validly signed forged bounce notifications that could revoke a targeted user's email. This was possible because the webhook verified SNS messages were signed by Amazon but did not bind them to trusted TopicArn values. The vulnerability was addressed in Discourse vers [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-49256

CVE-2026-49256 is a vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories could leak to anonymous and unauthorized users. This issue has been fixed in the mentioned versions. The vulnerability involves restricted tag and tag-group names attached to publicly re [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-46413

CVE-2026-46413 is a MEDIUM-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could bypass intended access controls and route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue has been fixed in the mentioned versions. The vulnerability allows unauthorized data s [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-45788

CVE-2026-45788 is a vulnerability in Discourse that could expose secure uploads when an attacker knows the secured upload URL and the secure_uploads site setting is enabled. The issue was fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. This vulnerability has a medium severity and is related to the pull_hotlinked_images feature. Users of Discourse, especially those who have enabled secure upl [truncated]

MEDIUM discourse CVE published 2026-07-09

CVE-2026-45780

CVE-2026-45780 is an information disclosure vulnerability in Discourse's EventSerializer. The issue allows users who can view a topic but not the private event invitee list to see invited group names, sample invitees, and attendance statistics. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability arises from inadequate access controls in the EventSerializer, which [truncated]

HIGH discourse CVE published 2026-07-09

CVE-2026-44787

CVE-2026-44787 is a high-severity vulnerability in the Discourse discussion platform, affecting the signup flow and allowing newly registered users to gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability has a high CVSS score of 8.2 and is considered [truncated]

HIGH discourse CVE published 2026-07-09

CVE-2026-55420

CVE-2026-55420 is a high-severity vulnerability in Discourse that allows for remote code execution (RCE) via PDF uploads under certain non-default server-side configurations. This issue was patched in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability exists due to improper handling of PDF uploads, which can be exploited under specific configurations. Users of Discourse should be aware [truncated]

MEDIUM discourse CVE published 2026-06-12

CVE-2026-47264

CVE-2026-47264 is an information disclosure vulnerability in Discourse's DetailedTagSerializer. Versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1 are affected. The vulnerability allows anonymous and unprivileged users to read the names of tag groups restricted to specific user groups or non-visible categories when SiteSetting.tags_liste [truncated]

MEDIUM discourse CVE published 2026-06-12

CVE-2026-47263

CVE-2026-47263 is a medium-severity vulnerability in Discourse, an open-source discussion platform. The issue allows authenticated users to access webhook events due to a missing group ID in the MessageBus.publish call. This vulnerability affects Discourse versions from 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. The vulnerability has bee [truncated]