Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2026.1.0-latest
- >= 2026.2.0-latest
A SQL injection vulnerability has been identified in Discourse prior to versions 2025.12.2, 2026.1.1, and 2026.2.0. This vulnerability occurs in the private message tag filtering feature, specifically within the 'list_private_messages_tag' function. It allows users to bypass tag filter conditions, potentially leading to the unauthorized disclosure of private message metadata.
Exploitation of this vulnerability could result in unauthorized access to private message metadata by bypassing tag filter conditions.
Users are advised to upgrade to Discourse versions 2025.12.2, 2026.1.1, or 2026.2.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.