discourse
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting discourse.
- CVE-2026-45780Discourse: Private event sample invitees are serialized to non-invited event viewers5.3
- CVE-2026-53963Discourse: Stored-XSS in 2FA delete confirmation modal7.3
- CVE-2026-59828Discourse: Hidden post revisions leak through adjacent visible diffs5.3
- CVE-2026-44787Discourse: Signup-time primary_group_id assignment grants whisperer access8.2
- CVE-2026-53962Discourse: Insufficient SVG sanitization logic5.4
- CVE-2026-55424Discourse: Topic featured link susceptible to stored XSS5.4
- CVE-2026-45788Discourse: Secure uploads exposed by hotlinked image copying7.5
- CVE-2026-49256Discourse: Hidden tag names leaked via category serializers7.5
- CVE-2026-46413Discourse: Regular users can route multipart uploads into the admin backup store6.5
- CVE-2026-53961Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)6.5
- CVE-2026-55420Discourse: Remote code execution via pdf uploads7.5
- CVE-2026-47264Discourse: Don't leak restricted tag group names via tag info5.3
- CVE-2026-47263Discourse: Prevent webhook payload disclosure on event redelivery4.3
- CVE-2026-45775Discourse: Cross-site backup access via path traversal in multisite local backups6.8
- CVE-2026-45085Discourse: Chat misauthorization and information disclosure5.3