Discourse Security Vulnerabilities (CVEs)
Track 48 security vulnerabilities affecting Discourse products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability in Discourse allows attackers to obtain sensitive information about private resources through URL redirects. When users without pro...
Jan 28, 2026This CVE allows non-admin moderators in Discourse to view sensitive information in staff action logs that should be restricted to administrators only....
Jan 28, 2026This vulnerability allows moderators in Discourse to improperly convert private personal messages into public topics, violating user privacy expectati...
Jan 28, 2026This CVE allows moderators in Discourse to access the 'top_uploads' admin report, which should be restricted to administrators only. The report reveal...
Jan 28, 2026A privilege escalation vulnerability in Discourse allows non-admin moderators to bypass email-change restrictions, potentially enabling account takeov...
Jan 28, 2026This CVE allows Discourse moderators to view user archives containing private topic/post content, violating confidentiality. It affects Discourse inst...
Jan 28, 2026This CVE allows non-admin moderators with post ownership transfer permissions to change ownership of posts in private messages and restricted categori...
Jan 28, 2026This vulnerability allows authenticated users to submit specially crafted payloads to Discourse's drafts endpoint, causing O(n^2) processing that ties...
Jan 28, 2026This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Discourse's FinalDestination component where hostname validation can be bypas...
Jan 28, 2026This CVE describes an authorization bypass vulnerability in Discourse discussion platform where subscription endpoints lack proper ownership verificat...
Jan 28, 2026Discourse versions before 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application-level denial of service vulnerability in the username change f...
Jan 28, 2026This vulnerability in Discourse allows authenticated users to bypass AI persona access controls, gaining unauthorized access to staff-only AI personas...
Jan 28, 2026This vulnerability in Discourse allows attackers to upload HTML or XML files to S3 storage that can execute scripts in the context of the S3/CDN domai...
Jan 28, 2026This CVE describes a content-security-policy-mitigated cross-site scripting (XSS) vulnerability in Discourse's Math plugin when using the KaTeX varian...
Jan 28, 2026This vulnerability in Discourse allows attackers to discover users' full names even when the 'enable_names' setting is disabled, by using partial user...
Dec 30, 2025Discourse versions 3.5.0 and below contain an authorization bypass vulnerability in AI suggestion endpoints. Authenticated users can access restricted...
Oct 1, 2025Discourse versions before 3.4.7 and 3.5.0.beta8 have a session fixation vulnerability in WebAuthn 2FA implementation. When users authenticate with phy...
Jul 29, 2025Discourse users on vulnerable versions can continue to view their own 'whisper' posts even after being removed from groups with whisper permissions. T...
Jun 25, 2025Discourse versions before 3.5.0.beta6 are vulnerable to cross-site scripting (XSS) when social logins are used without Content Security Policy (CSP) e...
Jun 25, 2025This vulnerability allows HTML injection in Discourse email invitations when topic titles contain HTML. Attackers can inject malicious HTML into email...
Jun 9, 2025This vulnerability in Discourse allows attackers to execute arbitrary JavaScript within iframes when Codepen is included in the allowed_iframes settin...
Jun 9, 2025This CVE describes a data leak vulnerability in Discourse where unauthenticated users could view private content on the homepage of login-required sit...
May 5, 2025This vulnerability allows attackers to bypass the user limit for direct messages (DMs) in Discourse, potentially creating DMs that include every user ...
Apr 30, 2025Discourse users who disabled direct messaging in their preferences could still be added to group direct messages in specific circumstances. This affec...
Mar 26, 2025This vulnerability in Discourse allows authenticated users to send excessive URL requests to the inline onebox generation endpoint, causing denial of ...
Feb 4, 2025This vulnerability allows attackers to poison the anonymous cache in Discourse by crafting requests with specific headers, potentially causing visitor...
Feb 4, 2025This vulnerability allows attackers to poison the anonymous cache in Discourse through crafted XHR requests, potentially serving incomplete or manipul...
Feb 4, 2025This CVE allows attackers to execute arbitrary JavaScript in users' browsers by posting malicious onebox URLs in Discourse forums. It affects Discours...
Feb 4, 2025This vulnerability allows attackers to execute arbitrary JavaScript in users' browsers by posting malicious video placeholder HTML elements in Discour...
Feb 4, 2025Discourse sites using Discourse Connect (SSO) with local logins still enabled are vulnerable to authentication bypass. Attackers can create accounts a...
Dec 19, 2024This CVE describes a cross-site scripting (XSS) vulnerability in Discourse's lightbox thumbnail feature. When users click on lightbox thumbnails, mali...
Dec 19, 2024This vulnerability allows attackers to download Discourse backup files through nginx misconfiguration when using local storage. Only Discourse instanc...
Dec 19, 2024This vulnerability in Discourse allows authenticated users to create posts with many replies and then fetch them all at once, potentially causing deni...
Oct 7, 2024The Discourse Calendar plugin contains a cross-site scripting (XSS) vulnerability where malicious event names can execute arbitrary JavaScript when re...
Sep 12, 2024CVE-2024-21658 is a resource exhaustion vulnerability in the discourse-calendar plugin where overly generous region value length limits allow attacker...
Aug 30, 2024This vulnerability in Discourse allows attackers to submit extremely long tag group names in requests, which can cause resource exhaustion and reduce ...
Jul 30, 2024This vulnerability in Discourse allows attackers to manipulate the FastImage library to redirect requests to internal Discourse IP addresses, potentia...
Jul 3, 2024This vulnerability allows a rogue staff user with administrative privileges in Discourse to suspend other staff users, preventing them from logging in...
Jul 3, 2024This vulnerability in Discourse allows attackers to reduce availability through a denial-of-service attack by exploiting improper input validation in ...
Jul 3, 2024The CVE-2023-46241 vulnerability in the discourse-microsoft-auth plugin allows attackers to potentially take control of victims' Discourse accounts th...
Feb 21, 2024Discourse's message serializer mishandles expanded chat mentions (@all and @here), creating excessively large user arrays that can cause denial of ser...
Jan 12, 2024This vulnerability in the discourse-calendar plugin allows attackers to inject malicious scripts into event titles, leading to cross-site scripting (X...
Oct 16, 2023CVE-2023-44388 is a denial-of-service vulnerability in Discourse where malicious requests can rapidly fill production log files, causing servers to ru...
Oct 16, 2023Discourse chat messages can be read by unauthenticated attackers via a POST request to MessageBus, exposing private conversations. This affects all Di...
Oct 16, 2023This vulnerability in the discourse-encrypt plugin allows cross-site scripting (XSS) attacks when encrypted topic titles are improperly escaped. It af...
Sep 28, 2023CVE-2021-41163 is a critical remote code execution vulnerability in Discourse that allows attackers to execute arbitrary code on affected servers thro...
Oct 20, 2021Discourse had a vulnerability where private message titles and participant lists were exposed to unauthorized users when groups were included in messa...
Sep 20, 2021This Cross-Site Scripting (XSS) vulnerability in Discourse allows attackers to inject malicious scripts into d-popover tooltips, potentially compromis...
Aug 9, 2021Why Monitor Discourse Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 48+ known vulnerabilities affecting Discourse products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Discourse packages in under 60 seconds. No agents required - completely agentless scanning that works across Discourse deployments.
Free vulnerability database: Access detailed information about every Discourse CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Discourse CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions