Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2026.1.0-latest
- >= 2026.2.0-latest
A vulnerability in Discourse prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, allowed moderators to export user Chat direct messages through an overly permissive allowlist in the 'can_export_entity?' method. This flaw enabled the export of any entity not explicitly blocked, rather than adhering to a strict allowlist. The issue has been patched in versions 2025.12.2, 2026.1.1, and 2026.2.0.
Exploitation of this vulnerability allowed moderators to improperly export user Chat direct messages via the CSV export endpoint.
Users are advised to upgrade to Discourse versions 2025.12.2, 2026.1.1, or 2026.2.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.