These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-59828 is a medium-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue has been fixed in the mentioned versions. The vulnerability allows for the leakag [truncated]
CVE-2026-55424 is a high-severity vulnerability in Discourse, a popular open-source discussion platform. The vulnerability allows a user with permission to set a featured link to inject JavaScript when default Content Security Policy protections are modified or disabled. This issue was fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability exists in the topic list feature of Disco [truncated]
CVE-2026-53963 is a high-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. The vulnerability has a CVSS score of 7.3 and [truncated]
CVE-2026-53962 is a vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This vulnerability has a medium severity and could allow attackers to execute [truncated]
CVE-2026-53961 is a medium-severity vulnerability in Discourse's AWS SES bounce webhook. The issue allowed any AWS account holder to publish validly signed forged bounce notifications that could revoke a targeted user's email. This was possible because the webhook verified SNS messages were signed by Amazon but did not bind them to trusted TopicArn values. The vulnerability was addressed in Discourse vers [truncated]
CVE-2026-49256 is a vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories could leak to anonymous and unauthorized users. This issue has been fixed in the mentioned versions. The vulnerability involves restricted tag and tag-group names attached to publicly re [truncated]
CVE-2026-46413 is a MEDIUM-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could bypass intended access controls and route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue has been fixed in the mentioned versions. The vulnerability allows unauthorized data s [truncated]
CVE-2026-45788 is a vulnerability in Discourse that could expose secure uploads when an attacker knows the secured upload URL and the secure_uploads site setting is enabled. The issue was fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. This vulnerability has a medium severity and is related to the pull_hotlinked_images feature. Users of Discourse, especially those who have enabled secure upl [truncated]
CVE-2026-45780 is an information disclosure vulnerability in Discourse's EventSerializer. The issue allows users who can view a topic but not the private event invitee list to see invited group names, sample invitees, and attendance statistics. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability arises from inadequate access controls in the EventSerializer, which [truncated]
CVE-2026-44787 is a high-severity vulnerability in the Discourse discussion platform, affecting the signup flow and allowing newly registered users to gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability has a high CVSS score of 8.2 and is considered [truncated]
CVE-2026-55420 is a high-severity vulnerability in Discourse that allows for remote code execution (RCE) via PDF uploads under certain non-default server-side configurations. This issue was patched in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability exists due to improper handling of PDF uploads, which can be exploited under specific configurations. Users of Discourse should be aware [truncated]
CVE-2026-47264 is an information disclosure vulnerability in Discourse's DetailedTagSerializer. Versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1 are affected. The vulnerability allows anonymous and unprivileged users to read the names of tag groups restricted to specific user groups or non-visible categories when SiteSetting.tags_liste [truncated]
CVE-2026-47263 is a medium-severity vulnerability in Discourse, an open-source discussion platform. The issue allows authenticated users to access webhook events due to a missing group ID in the MessageBus.publish call. This vulnerability affects Discourse versions from 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. The vulnerability has bee [truncated]
CVE-2026-45775 is a MEDIUM severity vulnerability in Discourse, an open-source discussion platform. A path traversal issue in backup handling could allow an authenticated administrator on one site in a multisite deployment to access backup files belonging to another site when backups are stored locally. Specifically, an admin on Site A could potentially retrieve sensitive backup data from Site B (same hos [truncated]
CVE-2026-45085 is a MEDIUM-severity vulnerability (CVSS Score: 5.3) affecting the Discourse open-source discussion platform. Specifically, it impacts sites with the chat plugin enabled, and additionally requires discourse-calendar for the calendar issue. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosu [truncated]
CVE-2026-44786 is a HIGH severity vulnerability in Discourse, an open-source discussion platform. Chat events for public category channels were published to MessageBus without permission scoping. This allowed any MessageBus subscriber without chat enabled to receive chat message payloads in real time. The affected versions are from 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, an [truncated]
CVE-2026-44785 is a vulnerability in the Discourse open-source discussion platform. The AI 'explain' helper only checks can_see? on the post being explained, not its reply_to_post. This allows any authenticated user with access to the AI helper to read the raw contents of a hidden parent post by invoking 'Explain' on a reply to it. The affected versions are from 2026.1.0-latest to before 2026.1.4, 2026.3. [truncated]
CVE-2026-44784 is a vulnerability in Discourse, an open-source discussion platform. The issue affects versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. In these versions, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credentials in plaintext via the group history log (/groups/:name/log [truncated]
CVE-2026-44783 is a medium-severity vulnerability in the Discourse discussion platform. A flaw in handling replies to whisper posts allows authenticated users outside the groups configured in whispers_allowed_groups to post into a topic's staff-only whisper channel. The injected content is visible to whisperers (typically staff) alongside legitimate whispers. Only sites that have whispers enabled are affe [truncated]
CVE-2026-44782 is a vulnerability in Discourse, an open-source discussion platform. The issue involves an incorrect predicate in GroupPostSerializer, leading to unintended serialization of user names. Versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1 are affected. The vulnerability has been patched in versions 2026.1.4, 2026.3.1, 2026.4 [truncated]
CVE-2026-44780 is an information disclosure vulnerability affecting Discourse, an open-source discussion platform. The vulnerability exists in versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. The issue arises from the ReviewableQueuedPostSerializer unconditionally including payload[raw_email] for posts that arrived via incoming email. [truncated]
CVE-2026-44779 is a vulnerability in Discourse, an open-source discussion platform. Bot debug endpoints disclose whisper translation audit logs. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
CVE-2026-34154 is a low-severity access-control issue in Discourse’s discourse-subscriptions plugin. According to the official advisory and NVD record, affected deployments before 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1 could allow users to gain access to subscription-gated groups without completing payment. The flaw is tracked as CWE-862 (improper authorization) and was publicly disclosed on 2026-05-19.
An authenticated information disclosure vulnerability exists in Discourse's form templates feature. Affected versions fail to enforce category-level authorization checks when retrieving form template metadata, allowing any authenticated user to read template names and structured content intended for restricted categories. The vulnerability requires the form templates feature to be enabled and valid user a [truncated]
A vulnerability in Discourse, an open-source discussion platform, allows outdated cached AI summaries to leak removed content to anonymous and unprivileged users who cannot regenerate summaries. The issue affects versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1. The vulnerability stems from improper handling of cached AI-generated summaries when underlying content has been removed or [truncated]
CVE-2026-44028 was publicly disclosed on 2026-05-05 and updated on 2026-05-09. The issue affects Nix and Lix and centers on unbounded recursion in the NAR (Nix Archive) parser. In the affected code path, a stack overflow on a coroutine stack without a guard page can corrupt heap memory, which may lead to arbitrary code execution as the Nix daemon runs as root in multi-user deployments if ASLR hardening is [truncated]
CVE-2026-34947: Discourse Staged User Custom Fields and Username Exposure. A vulnerability in Discourse, an open-source discussion platform, allowed staged user custom fields and usernames to be exposed on public invite pages without email verification. This issue existed in versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, posing a lo [truncated]
CVE-2026-27481 is an authorization bypass vulnerability in Discourse, an open-source discussion platform. The vulnerability affects versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. It allows unauthenticated or unauthorized users to view hidden (staff-only) tags and its associated data. All Discourse instances with tagging enabled and [truncated]
CVE-2026-33415 is a vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view. This issue has been patched in versions 2026.1.3, 202 [truncated]
CVE-2026-33300 is an authorization bypass vulnerability in Discourse, a popular open-source discussion platform. The vulnerability affects versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The issue allows moderators to access information on hidden groups, including their names and user counts, via the Category Chatables Controller sho [truncated]
CVE-2026-33185 is a vulnerability in the Discourse open-source discussion platform. The group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports, potentially allowing probing of internal network infrastructure. This issue was patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The vulnerability allows non-staff group owners to initiat [truncated]
Discourse is vulnerable to a subscription tier issue. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription. This issue has significant implications for user account management and subscription services.
The Discourse discourse-subscriptions plugin has a vulnerability that leaks Stripe API keys across sites in a multisite cluster. This issue was patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The vulnerability affects versions from 2026.1.0-latest up to but not including 2026.1.3, 2026.2.0-latest up to but not including 2026.2.2, and 2026.3.0-latest. Users of the Discourse platform who utilize the d [truncated]
CVE-2026-32951 is an information disclosure vulnerability affecting Discourse, an open-source discussion platform. The issue allows an authenticated user to obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared drafts category. This vulnerability exists in versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 20 [truncated]
CVE-2026-32620 is a vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only metadata about who read the post and when. This issue has b [truncated]
CVE-2026-32619 is a medium-severity vulnerability affecting Discourse, an open-source discussion platform. The issue arises from versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. In these versions, users who have lost access to a topic, such as being removed from a private category group, could still interact with polls within that top [truncated]
CVE-2026-32618 is a vulnerability in Discourse, an open-source discussion platform, that allows for possible channel membership inference from chat user search without authorization. Versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0 are affected. The issue arises from inadequate authorization in the chat user search functionality, enabl [truncated]
Discourse users should review and apply patches to prevent category group moderators from performing privileged actions on topics inside private categories they do not have read access to. This vulnerability affects Discourse versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The issue has been patched in versions 2026.1.3, 2026.2.2, an [truncated]
CVE-2026-32607 is a low-severity vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escapin [truncated]
CVE-2026-32273 is a medium-severity vulnerability in Discourse, an open-source discussion platform. The issue, patched in versions 2026.1.3, 2026.2.2, and 2026.3.0, allows for cross-site scripting (XSS) attacks via unsanitized category descriptions updated through the API. This vulnerability exists due to a lack of sanitization in category description strings, which can lead to XSS attacks. Users of Disco [truncated]
Discourse, an open-source discussion platform, had a vulnerability allowing moderators to export CSV data for admin-restricted reports, bypassing visibility restrictions. This could expose sensitive operational data intended only for admins. The issue was patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The vulnerability existed due to insufficient access controls on report exports, which could be ex [truncated]
A vulnerability was discovered in the Discourse open-source discussion platform, affecting versions from 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true without validating the destination URL. This issue has been patched i [truncated]