Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2026.2.0-latest
- >= 2026.1.0-latest
A vulnerability in Discourse, an open-source discussion platform, allows unauthorized users to access the title and post excerpt through a user action API endpoint. This issue affects versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, and arises from a lack of visibility checks, leading to unauthorized information disclosure. The vulnerability has been patched in the mentioned versions, but no known workarounds are available.
Exploitation of this vulnerability results in unauthorized access to private topic titles and post excerpts, leading to information disclosure.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.