Vendor
Discourse vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 68 vulnerabilities in Discourse: 10 in the last 7 days and 38 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91121, was published on 24 September 2026. 1 technology has a page of its own.
- Last 7 days
- 10
- Last 90 days
- 38
- Critical, all time
- 1
- Exploited in the wild
- 0
About Discourse
Discourse is an open-source project and company providing modern forum software.
Discourse technologies
Latest Discourse vulnerabilities
- CVE-2026-91121: Discourse HTML injection in chat message excerptsmediumCVSS 5EPSS 0.3%
- CVE-2026-91120: Discourse HTML injection in lazy video embed notificationsmediumCVSS 5.4EPSS 0.2%
- CVE-2026-91119: Discourse stored HTML injection in activity log componentsmediumCVSS 6.4EPSS 0.2%
- CVE-2026-91134: Discourse post sanitizer iframe bypass via encoded userinfomediumCVSS 5.4EPSS 0.2%
- CVE-2026-91133: Discourse information disclosure in upload path queriesmediumCVSS 6.5EPSS 0.3%
- CVE-2026-91132: Discourse wildcard iframe origin allowlist bypassmediumCVSS 4.3EPSS 0.1%
- CVE-2026-91123: Discourse iframe src path traversal via backslash bypasshighCVSS 7.2EPSS 0.3%
- CVE-2026-91122: Discourse stored XSS in video placeholder componenthighCVSS 8.7EPSS 0.3%
- CVE-2026-84302: Discourse AI access control bypass in private message reviewablesmediumCVSS 4.2EPSS 0.2%
- CVE-2026-59830: Discourse stored XSS via unescaped display namemediumCVSS 5.4EPSS 0.3%
- CVE-2026-59829: Discourse information disclosure in category group moderation review queuemediumCVSS 4.3EPSS 0.4%
- CVE-2026-55704: Discourse shared-draft information disclosure in group serializationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-55674: Discourse stored XSS via color scheme cookiescriticalCVSS 9.3EPSS 0.6%
- CVE-2026-53960: Discourse hidden first-post content leakage in Q&A JSON-LD schemamediumCVSS 5.3EPSS 0.3%
- CVE-2026-72732: Discourse Templates endpoint information disclosure via tag filtering bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2026-72731: Discourse SQL injection in Data Explorer parameterized querieshighCVSS 7.1EPSS 0.4%
- CVE-2026-72730: Discourse stored XSS in Rich Text Editor chat transcript usernamehighCVSS 8.7EPSS 0.4%
- CVE-2026-72729: Discourse discourse-local-dates HTML injectioninfoEPSS 0.5%
- CVE-2026-72728: Discourse Onebox allowlist bypassmediumCVSS 6.3EPSS 0.3%
- CVE-2026-72727: Discourse stored XSS in moderation review queueinfoCVSS 4.8EPSS 0.4%
- CVE-2026-72726: Discourse AI bot reply stream information disclosuremediumCVSS 6.5EPSS 0.4%
- CVE-2026-72725: Discourse stored XSS in staff action logsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-72724: Discourse private chat message disclosure via oneboxmediumCVSS 4.3EPSS 0.6%
- CVE-2026-72723: Discourse information disclosure in anonymous navigation menu serializationmediumCVSS 5.3EPSS 0.5%
- CVE-2026-72722: Discourse information disclosure via duplicate lookup in TopicLinkmediumCVSS 4.3EPSS 0.4%
Most severe Discourse vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-55674: Discourse stored XSS via color scheme cookiescriticalCVSS 9.3EPSS 0.6%
- CVE-2026-72730: Discourse stored XSS in Rich Text Editor chat transcript usernamehighCVSS 8.7EPSS 0.4%
- CVE-2026-91122: Discourse stored XSS in video placeholder componenthighCVSS 8.7EPSS 0.3%
- CVE-2026-44787: Discourse privilege escalation in signup flowhighCVSS 8.2
- CVE-2026-44786: Discourse information disclosure in public chat channelshighCVSS 7.5EPSS 0.0%
- CVE-2026-55420: Discourse RCE via PDF upload processinghighCVSS 7.5
- CVE-2026-53963: Discourse stored XSS in 2FA delete confirmation dialoghighCVSS 7.3
- CVE-2026-91123: Discourse iframe src path traversal via backslash bypasshighCVSS 7.2EPSS 0.3%
- CVE-2026-72731: Discourse SQL injection in Data Explorer parameterized querieshighCVSS 7.1EPSS 0.4%
- CVE-2026-45775: Discourse path traversal in multisite backup handlingmediumCVSS 6.8EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 11 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 13 | 0 | |
| 17 Aug 2026 | 4 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 10 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/discourse.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Discourse vulnerabilities", https://junglewise.ai/threats/vendors/discourse, 26 September 2026.