In Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-25783 was detected. This vulnerability allows an authenticated attacker to trigger a denial of service by sending a specially crafted User-Agent header, causing a request panic due to improper validation of header tokens. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25783.
Read more CommunicationIn Mattermost Plugins versions 2.0.3.0 and earlier a medium severity vulnerability CVE-2026-2476 was detected. This vulnerability allows an attacker with access to support packets to obtain original plugin settings because sensitive configuration values are not properly masked in exported configuration data. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2476.
Read more CommunicationIn Mattermost Plugins versions 11.3, 11.0.3, 11.2.2, and 10.10.11.0 and earlier a medium severity vulnerability CVE-2026-2461 was detected. This vulnerability allows an authorized attacker with editor permissions to modify comments created by other board members due to missing authorization checks on comment block modifications. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2461.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0) and 11.2.x (≤ 11.2.2) a medium severity vulnerability CVE-2026-26304 was detected. This vulnerability allows team members to create unauthorized playbook runs via the playbook run API due to missing verification of the `run_create` permission for empty `playbookId`. To address this issue, users should upgrade Mattermost Server to version 11.3.1 or later (for 11.3.x branch) or version 11.2.3 or later (for 11.2.x branch). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26304.
Read more CommunicationIn Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27454 was detected. This vulnerability allows attackers to bypass authorization checks and access hidden post revisions by requesting specific version parameters in the /posts/:id.json endpoint. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27454.
Read more CommunicationIn Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27166 was detected. This vulnerability allows attackers to perform HTML injection by exploiting insufficient sanitization of the default Codepen allowed iframes, potentially tricking users into changing the main page URL. To address this issue, users should upgrade to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27166.
Read more CommunicationIn Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27491 was detected. This vulnerability allows non-staff users to issue official warnings to other users by exploiting a type coercion issue in a post actions API endpoint, bypassing intended staff-only restrictions. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27491.
In Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27570 was detected. This vulnerability allows attackers to execute stored cross-site scripting (XSS) by injecting malicious content into the conversation title, which is rendered without proper sanitization in the Shared AI Conversation onebox. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27570.
In Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27740 was detected. This vulnerability allows attackers to execute stored cross-site scripting (XSS) by injecting malicious payloads through AI-generated content, which is rendered without proper sanitization in the Review Queue interface. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27740.