In Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27153 was detected. This vulnerability allows moderators to export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in can_export_entity?, allowing export of any entity not explicitly blocked. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27153.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27152 was detected. This vulnerability allows users to bypass DM communication preferences when adding members via Chat::AddUsersToChannel, enabling them to add targets who have blocked, ignored, or muted them to an existing DM channel. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27152.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27152 was detected. This vulnerability allows users to bypass DM communication preferences when adding members via Chat::AddUsersToChannel, enabling them to add targets who have blocked, ignored or muted them to an existing DM channel. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27152.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27151 was detected. This vulnerability allows TL4 users and category group moderators to move posts into topics in categories where they lack posting privileges because the move_posts action only checked can_move_posts? on the source topic and did not validate write permissions on the destination topic. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27151.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a low severity vulnerability CVE-2026-28227 was detected. This vulnerability allows TL4 users to bypass authorization checks and publish topics into staff-only categories using the `publish_to_category` topic timer. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28227.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a low severity vulnerability CVE-2026-28219 was detected. This vulnerability allows authenticated users to bypass administrative restrictions and modify privileged topic attributes, enabling them to elevate a topic’s status to a site-wide notice or banner via manipulated PUT or POST requests. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28219.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-28218 was detected. This vulnerability allows any authenticated user to execute SQL queries in the Data Explorer plugin that have no explicit group assignments, including built-in system queries, due to fail-open access control. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28218.
Read more CommunicationIn Mattermost versions 11.1.x up to and including 11.1.2, 10.11.x up to and including 10.11.9, 11.2.x up to and including 11.2.1 and Mattermost Plugin Zoom versions up to and including 1.11.0 a medium severity vulnerability CVE-2026-0997 was detected. This vulnerability allows authenticated users to modify Zoom meeting restrictions for arbitrary channels via crafted API requests due to insufficient validation of the authenticated user in the /plugins/zoom/api/v1/channel-preference endpoint. To address this issue, users should upgrade Mattermost and the Mattermost Zoom Plugin to versions 11.3.0, 11.1.3, 10.11.10 or 11.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-0997.
Read more CommunicationIn Mattermost versions 10.11.x up to and including 10.11.9 a low severity vulnerability CVE-2025-14573 was detected. This vulnerability allows team administrators without proper invite permissions to bypass restrictions and add users to their team via crafted API requests due to improper enforcement of invite permission checks when updating team settings through the allow_open_invite field. To address this issue, users should upgrade to versions 11.3.0 or 10.11.10. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14573.
Read more Communication