discourse
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting discourse.
- CVE-2026-72732Discourse: Templates endpoint exposes hidden tag names4.3
- CVE-2026-72731Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer7.1
- CVE-2026-72730Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor8.7
- CVE-2026-72728Discourse: Onebox iframe origin allowlist enforces URL authority boundary6.3
- CVE-2026-72726Discourse: Unauthorized eavesdropping on private AI bot conversations.6.5
- CVE-2026-72725Discourse: Stored XSS in staff action logs injects staff UI5.4
- CVE-2026-72724Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch4.3
- CVE-2026-72723Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted tags5.3
- CVE-2026-72722Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs4.3
- CVE-2026-72721Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison5.3
- CVE-2026-72720Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing6.4
- CVE-2026-45780Discourse: Private event sample invitees are serialized to non-invited event viewers5.3
- CVE-2026-53963Discourse: Stored-XSS in 2FA delete confirmation modal7.3
- CVE-2026-59828Discourse: Hidden post revisions leak through adjacent visible diffs5.3
- CVE-2026-44787Discourse: Signup-time primary_group_id assignment grants whisperer access8.2