In Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-26078 was detected. This vulnerability allows an attacker to forge valid Patreon webhook signatures when the `patreon_webhook_secret` site setting is blank, enabling unauthorized creation, modification, or deletion of Patreon pledge data and triggering patron-to-group synchronization. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26078.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-26077 was detected. This vulnerability allows unauthenticated attackers to forge webhook payloads on several endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) when no authentication token is configured, potentially inflating user bounce scores and causing legitimate user emails to be disabled. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26077.
Read more CommunicationIn Dolibarr ERP/CRM version 10.0.1 a high severity vulnerability CVE-2019-25452 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries via the `elemid` POST parameter in the `viewcat.php` endpoint, potentially exposing sensitive database information through error-based or time-based blind SQL injection. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2019-25452.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27150 was detected. This vulnerability allows any logged-in user to create bookmarks for query groups they do not have access to due to missing validate_before_create authorization in Data Explorer’s QueryGroupBookmarkable, enabling metadata disclosure via bookmark reminder notifications. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27150.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a medium severity vulnerability CVE-2026-27149 was detected. This vulnerability allows attackers to bypass tag filter conditions in PM tag filtering (list_private_messages_tag), potentially disclosing unauthorized private message metadata. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27149.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a medium severity vulnerability CVE-2026-27021 was detected. This vulnerability allows attackers to access voter details of polls in any post due to missing post visibility checks in the voters endpoint of the poll plugin. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27021.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-26979 was detected. This vulnerability allows TL4 users to close, archive, and pin topics in private categories they do not have access to. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26979.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-27162 was detected. This vulnerability allows authenticated users to access posts that should be restricted, including whispers, because the `posts_nearby` endpoint returned all posts regardless of type without properly filtering by user permissions. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27162.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27152 was detected. This vulnerability allows users to bypass DM communication preferences when adding members via Chat::AddUsersToChannel, enabling them to add targets who have blocked, ignored or muted them to an existing DM channel. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27152.
Read more Communication