In Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a medium severity vulnerability CVE-2026-27162 was detected. This vulnerability allows authenticated users to access posts that should be restricted, including whispers, because the `posts_nearby` endpoint returned all posts regardless of type without properly filtering by user permissions. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27162.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27154 was detected. This vulnerability allows attackers to execute XSS by having a user full name evaluated as raw HTML when display_name_on_posts is set to true and prioritize_username_in_ux is set to false. Editing a post of a malicious user would trigger the XSS. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27154.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27153 was detected. This vulnerability allows moderators to export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in can_export_entity?, allowing export of any entity not explicitly blocked. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27153.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27152 was detected. This vulnerability allows users to bypass DM communication preferences when adding members via Chat::AddUsersToChannel, enabling them to add targets who have blocked, ignored, or muted them to an existing DM channel. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27152.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27152 was detected. This vulnerability allows users to bypass DM communication preferences when adding members via Chat::AddUsersToChannel, enabling them to add targets who have blocked, ignored or muted them to an existing DM channel. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27152.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1 and 2026.2.0 a low severity vulnerability CVE-2026-27151 was detected. This vulnerability allows TL4 users and category group moderators to move posts into topics in categories where they lack posting privileges because the move_posts action only checked can_move_posts? on the source topic and did not validate write permissions on the destination topic. To address this issue users must upgrade to Discourse versions 2025.12.2, 2026.1.1 or 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27151.
Read more CommunicationIn changedetection.io versions prior to 0.54.1 a medium severity vulnerability CVE-2026-27645 was detected. This vulnerability allows an attacker to perform Reflected Cross-Site Scripting (XSS) via the RSS single-watch endpoint, where the UUID path parameter is reflected in the HTTP response without HTML escaping, leading to execution of arbitrary JavaScript in the user’s browser. To address this issue, users should upgrade changedetection.io to version 0.54.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27645.
Read more MonitoringIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a low severity vulnerability CVE-2026-28227 was detected. This vulnerability allows TL4 users to bypass authorization checks and publish topics into staff-only categories using the `publish_to_category` topic timer. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28227.
Read more CommunicationIn Discourse versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 a low severity vulnerability CVE-2026-28219 was detected. This vulnerability allows authenticated users to bypass administrative restrictions and modify privileged topic attributes, enabling them to elevate a topic’s status to a site-wide notice or banner via manipulated PUT or POST requests. To address this issue, users should upgrade Discourse to versions 2025.12.2, 2026.1.1, 2026.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28219.
Read more Communication