discourse
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting discourse.
- CVE-2026-59830Discourse: Stored XSS via unescaped actor name in post actions5.4
- CVE-2026-53960Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD5.3
- CVE-2026-55704Discourse: Shared-draft titles and excerpts leak through group post serialization4.3
- CVE-2026-55674Discourse: Cache poisoning/XSS via color scheme cookies9.3
- CVE-2026-59829Discourse: Review queue exposes flag-related private message excerpts to category group moderators4.3
- CVE-2026-72732Discourse: Templates endpoint exposes hidden tag names4.3
- CVE-2026-72731Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer7.1
- CVE-2026-72730Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor8.7
- CVE-2026-72729Discourse: Stored XSS in discourse-local-dates plugin
- CVE-2026-72728Discourse: Onebox iframe origin allowlist enforces URL authority boundary6.3
- CVE-2026-72727Discourse: Stored XSS in the moderation review queue
- CVE-2026-72726Discourse: Unauthorized eavesdropping on private AI bot conversations.6.5
- CVE-2026-72725Discourse: Stored XSS in staff action logs injects staff UI5.4
- CVE-2026-72724Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch4.3
- CVE-2026-72723Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tags5.3