Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2026.1.0-latest
- >= 2026.2.0-latest
A vulnerability exists in the Discourse poll plugin, specifically in versions prior to 2025.12.2, 2026.1.1, and 2026.2.0. The issue arises because the voters endpoint did not implement proper post visibility checks. This oversight allowed unauthorized users to access details about voters in any poll post. The vulnerability could be exploited without any special requirements or privileges.
Exploitation of this vulnerability led to unauthorized access to voter details in polls, potentially allowing users to see how others voted in any post.
Users can upgrade to Discourse versions 2025.12.2, 2026.1.1, or 2026.2.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.