Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 2026.2.0-latest
- >= 2026.1.0-latest
A vulnerability exists in Discourse versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, allowing users with tag-editing permissions to modify and create synonyms for tags concealed in restricted groups. This could be done without having visibility into those tags. The issue has been addressed in the mentioned patched versions.
This vulnerability could lead to unauthorized editing and synonym creation for tags in restricted groups, potentially disrupting tag organization and management.
Users are advised to upgrade to Discourse versions 2026.3.0-latest.1, 2026.2.1, or 2026.1.2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.