Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 2026.2.0-latest
- >= 2026.1.0-latest
A vulnerability in Discourse's Post Edits admin report feature allowed unauthorized access to private message content and secure category posts. Moderators could inadvertently view the first 40 characters of raw post edits from these restricted areas, violating privacy protocols. This issue affected Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
The vulnerability could lead to unauthorized disclosure of private message content and secure category posts to moderators.
The vulnerability can be reproduced by accessing the Post Edits admin report as a moderator. This will reveal leaked content from private messages and secure categories.
Users can upgrade to Discourse versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.