In Mattermost Plugins versions 11.3, 11.0.3, 11.2.2, and 10.10.11.0 and earlier a medium severity vulnerability CVE-2026-2461 was detected. This vulnerability allows an authorized attacker with editor permissions to modify comments created by other board members due to missing authorization checks on comment block modifications. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2461.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0) and 11.2.x (≤ 11.2.2) a medium severity vulnerability CVE-2026-26304 was detected. This vulnerability allows team members to create unauthorized playbook runs via the playbook run API due to missing verification of the `run_create` permission for empty `playbookId`. To address this issue, users should upgrade Mattermost Server to version 11.3.1 or later (for 11.3.x branch) or version 11.2.3 or later (for 11.2.x branch). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26304.
Read more CommunicationIn Jenkins versions 2.554 and earlier, and LTS versions 2.541.2 and earlier a high severity vulnerability CVE-2026-33001 was detected. This vulnerability allows attackers with Item/Configure permissions to write arbitrary files on the filesystem by exploiting unsafe symbolic link handling during the extraction of .tar and .tar.gz archives. To address this issue, users should upgrade Jenkins to versions beyond 2.555 or beyond LTS 2.541.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33001.
Read more Developer ToolsIn Kanboard versions prior to 1.2.51 a high severity vulnerability CVE-2026-33058 was detected. This vulnerability allows attackers with permission to add users to a project to perform SQL injection and dump the entire Kanboard database. To address this issue, users should upgrade Kanboard to version 1.2.51. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33058.
Read more Project ManagementIn Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27454 was detected. This vulnerability allows attackers to bypass authorization checks and access hidden post revisions by requesting specific version parameters in the /posts/:id.json endpoint. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27454.
Read more CommunicationIn Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27166 was detected. This vulnerability allows attackers to perform HTML injection by exploiting insufficient sanitization of the default Codepen allowed iframes, potentially tricking users into changing the main page URL. To address this issue, users should upgrade to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27166.
Read more CommunicationIn Jenkins versions 2.442 through 2.554 and LTS versions 2.426.3 through 2.541.2 a high severity vulnerability CVE-2026-33002 was detected. This vulnerability allows attackers to bypass origin validation on the CLI WebSocket endpoint by exploiting DNS rebinding, due to origin checks relying on the Host or X-Forwarded-Host HTTP headers. To address this issue, users should upgrade Jenkins to versions beyond 2.554 or beyond LTS 2.541.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-33002.
Read more Developer ToolsIn Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27491 was detected. This vulnerability allows non-staff users to issue official warnings to other users by exploiting a type coercion issue in a post actions API endpoint, bypassing intended staff-only restrictions. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27491.
In Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 a medium severity vulnerability CVE-2026-27570 was detected. This vulnerability allows attackers to execute stored cross-site scripting (XSS) by injecting malicious content into the conversation title, which is rendered without proper sanitization in the Shared AI Conversation onebox. To address this issue, users should upgrade Discourse to versions 2026.3.0-latest.1, 2026.2.1 or 2026.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27570.