These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-59829 is a medium-severity vulnerability affecting the Discourse open-source discussion platform. It allows category group moderators to access excerpts of private messages attached to flags, even if they are not participants in those messages. This issue is fixed in Discourse versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1. The vulnerability affects sites with category group moderation enabl [truncated]
CVE-2026-55704 is an information disclosure vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users with permission to view a group's activity but not shared drafts could still access shared-draft entries through group posts and mentions. This could reveal unpublished draft material, including topic titles and post excerpts. The i [truncated]
CVE-2026-55674 is a critical vulnerability in Discourse, an open-source discussion platform. An unauthenticated attacker can inject arbitrary HTML into a Discourse page by sending a crafted cookie request, allowing for arbitrary JavaScript execution in visitors' browsers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The vulnerability requires immediate attention from defende [truncated]
Discourse platform vulnerability leaks hidden post content in QAPage JSON-LD structured data, exposing sensitive information to unauthenticated visitors and search engines. This issue requires immediate attention and remediation to prevent content exposure. The vulnerability affects Discourse installations prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Affected administrators and users with [truncated]
CVE-2026-72732 is a vulnerability in the Discourse open-source discussion platform. The discourse_templates endpoint exposed hidden tag names due to a flawed serializer that did not filter tags through the request Guardian, allowing users to see tags they were not permitted to view. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVE-2026-72731 is a high-severity vulnerability in the Discourse open-source discussion platform. Affected versions include 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1. The issue allows unauthorized SQL execution through the Data Explorer plugin, enabling any table to be read but not modified. This vulnerability has significant implications for Discourse administrators and us [truncated]
CVE-2026-72730 is a high-severity vulnerability in the Discourse platform, an open-source discussion platform. The vulnerability allows for stored cross-site scripting (XSS) attacks due to the Rich Text Editor rendering chat-transcript usernames as HTML. This issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Affected deployments should prioritize upgrading to prevent potential XSS at [truncated]
CVE-2026-72729 is a vulnerability in the discourse-local-dates plugin for Discourse, an open-source discussion platform. The plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Defenders should assess exposure and update to a fixed version if necessary. The [truncated]
CVE-2026-72728 is a medium-severity vulnerability in the Discourse open-source discussion platform. An authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. The issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1. This vulnerability allows attackers to inject malicious content, potentially leading to un [truncated]
CVE-2026-72727 is a stored cross-site scripting (XSS) vulnerability in the Discourse open-source discussion platform. A low-privileged user could place crafted content in the moderation review queue that executed stored XSS when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVE-2026-72726 is a vulnerability in the Discourse open-source discussion platform that allows an authenticated user to eavesdrop on private AI bot conversations through the AI bot reply stream. The issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. This vulnerability impacts Discourse instances using AI bots, allowing unauthorized access to sensitive conversations. Defenders should a [truncated]
CVE-2026-72725 is a medium-severity vulnerability in the Discourse open-source discussion platform. Prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the staff action log model rendered unescaped previous and new value fields, potentially allowing stored cross-site scripting (XSS) attacks in the staff interface. This vulnerability could allow attackers to inject malicious scripts into the staf [truncated]
CVE-2026-72724 is a vulnerability in the Discourse open-source discussion platform that allows an authenticated user to obtain private thread message content by pairing a public channel ID with a private thread ID in a /onebox.json request. This issue was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. The vulnerability exists due to inadequate access controls in the chat plugin, specificall [truncated]
CVE-2026-72723 is a vulnerability in Discourse, an open-source discussion platform. The issue allows an unauthenticated user to retrieve restricted tag names and descriptions through /site.json when those tags are limited by inaccessible categories, category tag groups, or tag-group permissions. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
An authenticated user can submit links to restricted topics, private messages, or hidden posts and receive canonicalized slugs or titles in the composer_messages duplicate_lookup response even though the targets are not visible to that user. This issue affects Discourse, an open-source discussion platform, where TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not cons [truncated]
CVE-2026-72721 is a medium-severity vulnerability in the Discourse platform that allows an attacker to bypass Onebox domain restrictions by manipulating hostname casing. This issue arises from the case-sensitive comparison of hostnames and blocked_onebox_domains entries in Onebox::DomainChecker.is_blocked?. The vulnerability was fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. Affected Discou [truncated]
Discourse users should assess exposure and prioritize verification of Vimeo iframe and secure-upload URL handling. This involves reviewing the PrettyText.format_for_email feature, which has an HTML injection vulnerability. The vulnerability allows crafted Vimeo iframe sources, secure-upload URLs, or dimensions, and hashtag data-slug values to cause decoded attribute text to be reinterpreted as HTML. Affec [truncated]
CVE-2026-59828 is a medium-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue has been fixed in the mentioned versions. The vulnerability allows for the leakag [truncated]
CVE-2026-55424 is a high-severity vulnerability in Discourse, a popular open-source discussion platform. The vulnerability allows a user with permission to set a featured link to inject JavaScript when default Content Security Policy protections are modified or disabled. This issue was fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability exists in the topic list feature of Disco [truncated]
CVE-2026-53963 is a high-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. The vulnerability has a CVSS score of 7.3 and [truncated]
CVE-2026-53962 is a vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This vulnerability has a medium severity and could allow attackers to execute [truncated]
CVE-2026-53961 is a medium-severity vulnerability in Discourse's AWS SES bounce webhook. The issue allowed any AWS account holder to publish validly signed forged bounce notifications that could revoke a targeted user's email. This was possible because the webhook verified SNS messages were signed by Amazon but did not bind them to trusted TopicArn values. The vulnerability was addressed in Discourse vers [truncated]
CVE-2026-49256 is a vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories could leak to anonymous and unauthorized users. This issue has been fixed in the mentioned versions. The vulnerability involves restricted tag and tag-group names attached to publicly re [truncated]
CVE-2026-46413 is a MEDIUM-severity vulnerability in Discourse, an open-source discussion platform. Prior to versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could bypass intended access controls and route direct S3 multipart uploads through ExternalUploadManager into the admin backup store. This issue has been fixed in the mentioned versions. The vulnerability allows unauthorized data s [truncated]
CVE-2026-45788 is a vulnerability in Discourse that could expose secure uploads when an attacker knows the secured upload URL and the secure_uploads site setting is enabled. The issue was fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. This vulnerability has a medium severity and is related to the pull_hotlinked_images feature. Users of Discourse, especially those who have enabled secure upl [truncated]
CVE-2026-45780 is an information disclosure vulnerability in Discourse's EventSerializer. The issue allows users who can view a topic but not the private event invitee list to see invited group names, sample invitees, and attendance statistics. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability arises from inadequate access controls in the EventSerializer, which [truncated]
CVE-2026-44787 is a high-severity vulnerability in the Discourse discussion platform, affecting the signup flow and allowing newly registered users to gain whisper-group privileges without legitimate group membership on sites with whispers_allowed_groups configured. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability has a high CVSS score of 8.2 and is considered [truncated]
CVE-2026-55420 is a high-severity vulnerability in Discourse that allows for remote code execution (RCE) via PDF uploads under certain non-default server-side configurations. This issue was patched in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability exists due to improper handling of PDF uploads, which can be exploited under specific configurations. Users of Discourse should be aware [truncated]
CVE-2026-47264 is an information disclosure vulnerability in Discourse's DetailedTagSerializer. Versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1 are affected. The vulnerability allows anonymous and unprivileged users to read the names of tag groups restricted to specific user groups or non-visible categories when SiteSetting.tags_liste [truncated]
CVE-2026-47263 is a medium-severity vulnerability in Discourse, an open-source discussion platform. The issue allows authenticated users to access webhook events due to a missing group ID in the MessageBus.publish call. This vulnerability affects Discourse versions from 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. The vulnerability has bee [truncated]