Discourse operates a widely deployed community and discussion platform that serves as a hosted or self-managed communication hub for organizations, forums, and customer communities. Despite a compact product portfolio centered on the core platform and extensions such as calendar and chat functionality, the vendor's vulnerability footprint is substantial and reflects the platform's prominent role in the web application landscape. The recurring exposure concentrates in information-disclosure, cross-site scripting, authorization, and input-validation weakness classes that are characteristic of feature-rich web applications handling user-generated content and authentication. Defenders should treat Discourse instances as high-value targets for regular patching, particularly those exposed to the internet or hosting sensitive community data; live severity and current exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Discourse over time
Signals from CVEs in this vendor scope (290 CVEs).
290 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41163CRITICAL Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of v | Oct 20, 2021 | 9.8 | 40 | NO | NO |
CVE-2026-53963CRITICAL Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escap | Jul 9, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-55420HIGH Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be e | Jul 9, 2026 | 8.1 | 36 | NO | NO |
CVE-2024-53991MEDIUM Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and | Dec 19, 2024 | 5.9 | 36 | NO | YES |
CVE-2026-49256HIGH Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as | Jul 9, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-44787HIGH Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and | Jul 9, 2026 | 7.1 | 33 | NO | NO |
CVE-2026-45788HIGH Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2024-47773HIGH Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. Thi | Oct 8, 2024 | 8.2 | 33 | NO | YES |
CVE-2023-45131HIGH Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3 | Oct 16, 2023 | 7.5 | 32 | NO | YES |
CVE-2025-68662CRITICAL Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassi | Jan 28, 2026 | 9.9 | 31 | NO | NO |
Signals from CVEs in this vendor scope (290 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Discourse.
Media articles that mention a CVE ID that affects a product developed by Discourse — matched by CVE ID, not by vendor name.