These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-45775 is a MEDIUM severity vulnerability in Discourse, an open-source discussion platform. A path traversal issue in backup handling could allow an authenticated administrator on one site in a multisite deployment to access backup files belonging to another site when backups are stored locally. Specifically, an admin on Site A could potentially retrieve sensitive backup data from Site B (same hos [truncated]
CVE-2026-45085 is a MEDIUM-severity vulnerability (CVSS Score: 5.3) affecting the Discourse open-source discussion platform. Specifically, it impacts sites with the chat plugin enabled, and additionally requires discourse-calendar for the calendar issue. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosu [truncated]
CVE-2026-44786 is a HIGH severity vulnerability in Discourse, an open-source discussion platform. Chat events for public category channels were published to MessageBus without permission scoping. This allowed any MessageBus subscriber without chat enabled to receive chat message payloads in real time. The affected versions are from 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, an [truncated]
CVE-2026-44785 is a vulnerability in the Discourse open-source discussion platform. The AI 'explain' helper only checks can_see? on the post being explained, not its reply_to_post. This allows any authenticated user with access to the AI helper to read the raw contents of a hidden parent post by invoking 'Explain' on a reply to it. The affected versions are from 2026.1.0-latest to before 2026.1.4, 2026.3. [truncated]
CVE-2026-44784 is a vulnerability in Discourse, an open-source discussion platform. The issue affects versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. In these versions, group owners who are not necessarily admins or moderators can view a group's outgoing email/SMTP credentials in plaintext via the group history log (/groups/:name/log [truncated]
CVE-2026-44783 is a medium-severity vulnerability in the Discourse discussion platform. A flaw in handling replies to whisper posts allows authenticated users outside the groups configured in whispers_allowed_groups to post into a topic's staff-only whisper channel. The injected content is visible to whisperers (typically staff) alongside legitimate whispers. Only sites that have whispers enabled are affe [truncated]
CVE-2026-44782 is a vulnerability in Discourse, an open-source discussion platform. The issue involves an incorrect predicate in GroupPostSerializer, leading to unintended serialization of user names. Versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1 are affected. The vulnerability has been patched in versions 2026.1.4, 2026.3.1, 2026.4 [truncated]
CVE-2026-44780 is an information disclosure vulnerability affecting Discourse, an open-source discussion platform. The vulnerability exists in versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1. The issue arises from the ReviewableQueuedPostSerializer unconditionally including payload[raw_email] for posts that arrived via incoming email. [truncated]
CVE-2026-44779 is a vulnerability in Discourse, an open-source discussion platform. Bot debug endpoints disclose whisper translation audit logs. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.
CVE-2026-34154 is a low-severity access-control issue in Discourse’s discourse-subscriptions plugin. According to the official advisory and NVD record, affected deployments before 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1 could allow users to gain access to subscription-gated groups without completing payment. The flaw is tracked as CWE-862 (improper authorization) and was publicly disclosed on 2026-05-19.
An authenticated information disclosure vulnerability exists in Discourse's form templates feature. Affected versions fail to enforce category-level authorization checks when retrieving form template metadata, allowing any authenticated user to read template names and structured content intended for restricted categories. The vulnerability requires the form templates feature to be enabled and valid user a [truncated]
A vulnerability in Discourse, an open-source discussion platform, allows outdated cached AI summaries to leak removed content to anonymous and unprivileged users who cannot regenerate summaries. The issue affects versions prior to 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1. The vulnerability stems from improper handling of cached AI-generated summaries when underlying content has been removed or [truncated]
CVE-2026-44028 was publicly disclosed on 2026-05-05 and updated on 2026-05-09. The issue affects Nix and Lix and centers on unbounded recursion in the NAR (Nix Archive) parser. In the affected code path, a stack overflow on a coroutine stack without a guard page can corrupt heap memory, which may lead to arbitrary code execution as the Nix daemon runs as root in multi-user deployments if ASLR hardening is [truncated]
CVE-2026-34947: Discourse Staged User Custom Fields and Username Exposure. A vulnerability in Discourse, an open-source discussion platform, allowed staged user custom fields and usernames to be exposed on public invite pages without email verification. This issue existed in versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, posing a lo [truncated]
CVE-2026-27481 is an authorization bypass vulnerability in Discourse, an open-source discussion platform. The vulnerability affects versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. It allows unauthenticated or unauthorized users to view hidden (staff-only) tags and its associated data. All Discourse instances with tagging enabled and [truncated]
CVE-2026-33415 is a vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view. This issue has been patched in versions 2026.1.3, 202 [truncated]
CVE-2026-33300 is an authorization bypass vulnerability in Discourse, a popular open-source discussion platform. The vulnerability affects versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The issue allows moderators to access information on hidden groups, including their names and user counts, via the Category Chatables Controller sho [truncated]
CVE-2026-33185 is a vulnerability in the Discourse open-source discussion platform. The group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports, potentially allowing probing of internal network infrastructure. This issue was patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The vulnerability allows non-staff group owners to initiat [truncated]
Discourse is vulnerable to a subscription tier issue. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription. This issue has significant implications for user account management and subscription services.
The Discourse discourse-subscriptions plugin has a vulnerability that leaks Stripe API keys across sites in a multisite cluster. This issue was patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The vulnerability affects versions from 2026.1.0-latest up to but not including 2026.1.3, 2026.2.0-latest up to but not including 2026.2.2, and 2026.3.0-latest. Users of the Discourse platform who utilize the d [truncated]
CVE-2026-32951 is an information disclosure vulnerability affecting Discourse, an open-source discussion platform. The issue allows an authenticated user to obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared drafts category. This vulnerability exists in versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 20 [truncated]
CVE-2026-32620 is a vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only metadata about who read the post and when. This issue has b [truncated]
CVE-2026-32619 is a medium-severity vulnerability affecting Discourse, an open-source discussion platform. The issue arises from versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. In these versions, users who have lost access to a topic, such as being removed from a private category group, could still interact with polls within that top [truncated]
CVE-2026-32618 is a vulnerability in Discourse, an open-source discussion platform, that allows for possible channel membership inference from chat user search without authorization. Versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0 are affected. The issue arises from inadequate authorization in the chat user search functionality, enabl [truncated]
Discourse users should review and apply patches to prevent category group moderators from performing privileged actions on topics inside private categories they do not have read access to. This vulnerability affects Discourse versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The issue has been patched in versions 2026.1.3, 2026.2.2, an [truncated]
CVE-2026-32607 is a low-severity vulnerability in Discourse, an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escapin [truncated]
CVE-2026-32273 is a medium-severity vulnerability in Discourse, an open-source discussion platform. The issue, patched in versions 2026.1.3, 2026.2.2, and 2026.3.0, allows for cross-site scripting (XSS) attacks via unsanitized category descriptions updated through the API. This vulnerability exists due to a lack of sanitization in category description strings, which can lead to XSS attacks. Users of Disco [truncated]
Discourse, an open-source discussion platform, had a vulnerability allowing moderators to export CSV data for admin-restricted reports, bypassing visibility restrictions. This could expose sensitive operational data intended only for admins. The issue was patched in versions 2026.1.3, 2026.2.2, and 2026.3.0. The vulnerability existed due to insufficient access controls on report exports, which could be ex [truncated]
A vulnerability was discovered in the Discourse open-source discussion platform, affecting versions from 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0. The enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true without validating the destination URL. This issue has been patched i [truncated]