In Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-26077 was detected. This vulnerability allows unauthenticated attackers to forge webhook payloads on several endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) when no authentication token is configured, potentially inflating user bounce scores and causing legitimate user emails to be disabled. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26077.
Read more CommunicationIn Dolibarr ERP/CRM version 10.0.1 a high severity vulnerability CVE-2019-25452 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries via the `elemid` POST parameter in the `viewcat.php` endpoint, potentially exposing sensitive database information through error-based or time-based blind SQL injection. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2019-25452.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a medium severity vulnerability CVE-2026-27021 was detected. This vulnerability allows attackers to access voter details of polls in any post due to missing post visibility checks in the voters endpoint of the poll plugin. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27021.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-26979 was detected. This vulnerability allows TL4 users to close, archive, and pin topics in private categories they do not have access to. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26979.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-27162 was detected. This vulnerability allows authenticated users to access posts that should be restricted, including whispers, because the `posts_nearby` endpoint returned all posts regardless of type without properly filtering by user permissions. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27162.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27150 was detected. This vulnerability allows any logged-in user to create bookmarks for query groups they do not have access to due to missing validate_before_create authorization in Data Explorer’s QueryGroupBookmarkable, enabling metadata disclosure via bookmark reminder notifications. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27150.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a medium severity vulnerability CVE-2026-27149 was detected. This vulnerability allows attackers to bypass tag filter conditions in PM tag filtering (list_private_messages_tag), potentially disclosing unauthorized private message metadata. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27149.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27154 was detected. This vulnerability allows attackers to execute XSS by having a user full name evaluated as raw HTML when display_name_on_posts is set to true and prioritize_username_in_ux is set to false. Editing a post of a malicious user would trigger the XSS. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27154.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27153 was detected. This vulnerability allows moderators to export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in can_export_entity?, allowing export of any entity not explicitly blocked. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27153.
Read more Communication