Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2026.2.0-latest
- >= 2026.1.0-latest
A vulnerability in Discourse prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allows the IP address of flagged users to be visible to any user with access to the review queue. This exposure includes users who should not have access to IP address information.
This vulnerability allows for the unauthorized exposure of IP addresses of flagged users, potentially leading to privacy concerns.
Users are advised to upgrade to Discourse versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.