4.3

CVSS3.1

CVE-2026-32618 - Discourse: Unauthorized channel membership inference via excluded_memberships_channel_id

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in v…

πŸ“… Published: March 31, 2026, 5:40 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

5.3

CVSS4.0

CVE-2026-32615 - Discourse: Category group moderators can perform actions on topics in restricted categories without…

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside private categories they did not have read access…

πŸ“… Published: March 31, 2026, 5:40 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

2.1

CVSS4.0

CVE-2026-32607 - Discourse: Stored XSS via unescaped assignee name

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), u…

πŸ“… Published: March 31, 2026, 5:40 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

5.4

CVSS3.1

CVE-2026-32273 - Discourse: XSS on category description update via API

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue …

πŸ“… Published: March 31, 2026, 5:39 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

5.3

CVSS4.0

CVE-2026-32243 - Discourse: Stored XSS in discourse-ai shared conversations onebox

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject arbitrary HTML and JavaScript via crafted conver…

πŸ“… Published: March 31, 2026, 5:39 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

5.1

CVSS4.0

CVE-2026-32113 - Discourse: Open redirect via `sso_destination_url` cookie in `enter`

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true wi…

πŸ“… Published: March 31, 2026, 5:39 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

5.3

CVSS4.0

CVE-2026-32143 - Discourse: Admin-only report can be exported by moderators

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expo…

πŸ“… Published: March 31, 2026, 5:39 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

2

CVSS4.0

CVE-2026-33073 - discourse-subscriptions plugin leaking stripe API key in multisite environment

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a multisite cluster resulting in the potential for …

πŸ“… Published: March 31, 2026, 5:38 p.m. πŸ”„ Last Modified: April 10, 2026, 9:46 a.m.

5.3

CVSS4.0

CVE-2026-5206 - code-projects Simple Gym Management System Payment sql injection

A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql injection. Remote exploitati…

πŸ“… Published: March 31, 2026, 5:30 p.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

8.6

CVSS4.0

CVE-2026-2123 - Privilege escalation vulnerability in Operations Agent

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability

πŸ“… Published: March 31, 2026, 5:18 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.
Total resulsts: 349182
Page 774 of 34,919
Β« previous page Β» next page
Filters