Discourse
discourse.orgA fully open-source, self-hostable discussion platform usable as a mailing list, discussion forum, or long-form chat room.
- Homepage: discourse.org
- GitHub: github.com/discourse/discourse
- Privacy: discourse.org/privacy
- Web info: web-check.xyz/check/discourse.org
Discourse Privacy Policy
Privacy Policy Summary
- You can opt out of promotional communications
- This Service provides a list of Third Parties involved in its operation.
- This service gives your personal data to third parties involved in its operation
- If you are the target of a copyright holder's take down notice, this service gives you the opportunity to defend yourself
- This service is a subsidiary of Civilized Discourse Construction Kit, Inc.
- Information is provided about how your personal data is collected
- Your personal data is not sold
- Information is provided about what kind of personal information is collected
- Logs are deleted after a finite period of time
- You must create an account to use this service
- Your private content may be accessed by people working for the service
- Private messages can be read
- Extra data may be collected about you through promotions
- First-party cookies are used
- A list of all cookies set by the website is provided
- Third parties are involved in operating the service
- Two factor authentication is provided for your account
- Third-party cookies are used for advertising
- Your personal data may be used for marketing purposes
- Your data is processed and stored in a country that is less friendly to user privacy protection
- Third party cookies are employed, but with opt out instructions
- Do Not Track (DNT) headers are ignored and you are tracked anyway even if you set this header
- You can request access, correction and/or deletion of your data
- Your data may be processed and stored anywhere in the world
- The service will resist legal requests for your information where reasonably possible
- The service will try to inform and/or notify you regarding government inquiries that may involve your personal information
- The service claims to be CCPA compliant for California users
- You have the right to leave this service at any time
- This service will continue using anonymized user-generated content after erasure of personal information
- Third-party cookies are used for statistics
- A complaint mechanism is provided for the handling of personal data
- There is a date of the last update of the agreements
- The terms may be changed at any time, but you will receive notification of the changes
- Your personal data is aggregated into statistics
- The service is open-source
- Your personal data will not be used for an automated decision-making
- The service claims to be GDPR compliant for European users
- You can retrieve an archive of your data
- Many third parties are involved in operating the service
Score
Documents
- Copyright PolicyCreated 16 Jan 21, Last modified 2 months ago
- SubprocessorsCreated 24 Apr 26, Last modified 2 months ago
- Master Enterprise Hosting AgreementCreated 24 Apr 26, Last modified 2 months ago
- Self-Serve Hosting TermsCreated 24 Apr 26, Last modified 2 months ago
- Free Trial TermsCreated 24 Apr 26, Last modified 2 months ago
- Privacy PolicyCreated 16 Jan 21, Last modified 2 months ago
Domains Covered by Policy
- discourse.org
- rubytalk.org
About the Data
This data is kindly provided by tosdr.org. Read full report at: #1340
Discourse Source Code
Author
Description
A platform for community discussion. Free, open, simple.
Homepage
https://www.discourse.orgLicense
GPL-2.0
Created
12 Jan 13
Last Updated
12 Jul 26
Latest version
Primary Language
Ruby
Size
940,190 KB
Stars
47,446
Forks
8,947
Watchers
47,446
Language Usage
Star History
Top Contributors
-
@SamSaffron (7004)
-
@eviltrout (6610)
-
@tgxworld (5033)
-
@ZogStriP (4128)
-
@dependabot[bot] (3845)
-
@jjaffeux (3315)
-
@davidtaylorhq (3014)
-
@nlalonde (2682)
-
@awesomerobot (2215)
-
@coding-horror (2166)
-
@cvx (2134)
-
@arpitjalan (1966)
-
@martin-brennan (1821)
-
@pmusaraj (1422)
-
@gschlager (1154)
-
@nbianca (823)
-
@vinothkannans (742)
-
@KrisKotlarek (702)
-
@OsamaSayegh (630)
-
@xfalcox (520)
-
@chapoi (509)
-
@riking (506)
-
@romanrizzi (500)
-
@markvanlan (487)
-
@nattsw (473)
-
@discourse-translator-bot (436)
-
@oblakeerickson (431)
-
@danielwaterworth (414)
-
@Drenmi (406)
-
@dbattersby (386)
-
@dependabot-preview[bot] (385)
-
@jordanvidrine (381)
-
@udan11 (380)
-
@janzenisaac (379)
-
@renato (291)
-
@keegangeorge (289)
-
@AndrewPrigorshnev (283)
-
@Flink (265)
-
@megothss (245)
-
@featheredtoast (217)
-
@hnb-ku (203)
-
@jancernik (156)
-
@tyb-talks (139)
-
@vikhyat (137)
-
@Grubba27 (131)
-
@majakomel (126)
-
@Supermathie (122)
-
@pento (116)
-
@scossar (116)
-
@kubamracek (115)
-
@jbrw (108)
-
@s3lase (106)
-
@jomaxro (97)
-
@erickguan (94)
-
@xrav3nz (87)
-
@velesin (81)
-
@jdmartinez1062 (66)
-
@chrishunt (65)
-
@chancancode (64)
-
@cpradio (61)
-
@tshenry (60)
-
@gdpelican (59)
-
@tobiaseigen (53)
-
@pfaffman (53)
-
@rishabhnambiar (51)
-
@mcwumbly (50)
-
@khalilovcmded (47)
-
@Lhcfl (47)
-
@branquinhoaa (42)
-
@gnunicorn (41)
-
@blake-discourse (40)
-
@LeoMcA (40)
-
@angusmcleod (40)
-
@MeghnaAJ (39)
-
@ellaestigoy (36)
-
@abbat (35)
-
@tms (35)
-
@ofgeek (34)
-
@Elberet (33)
-
@jmperez127 (32)
-
@tannerabread (31)
-
@justindirose (31)
-
@ducks (31)
-
@nullchristo (30)
-
@mpalmer (30)
-
@Qasem-h (30)
-
@rngus2344 (27)
-
@merefield (26)
-
@dmacjam (26)
-
@mrfinch (25)
-
@sketchius (25)
-
@derekrushforth (24)
-
@marstall (24)
-
@small-lovely-cat (24)
-
@Canapin (23)
-
@caugner (21)
-
@nschonni (21)
-
@andrewschleifer (19)
-
@stephankaag (19)
-
@communiteq (19)
Recent Commits
-
SƩrgio Saquetim (10 Jul 26)
FIX: Make a11y.announce safe to call during render (#41629) `a11y.announce` updated its tracked announcement map synchronously, so calling it during render ā for example from an async data resolution that announces its result count ā tripped Ember's backtracking-rerender assertion ("attempted to update ⦠already used in the same computation") and broke the render. This defers the tracked write to the runloop with `next`, so it lands after the current render. Validation (message / type / delay) still throws synchronously, and `settled()` still awaits the deferred update, so callers and tests observe the announcement as before. A live region is polled asynchronously by screen readers, so the one-tick delay is imperceptible. Adds a regression test that announces from a getter read during render (alongside `<A11yLiveRegions />`) and asserts the announcement renders without a backtracking error.
-
Kris (10 Jul 26)
FIX: only show first paragraph of localized category descriptions (#41511) Reported here: https://meta.discourse.org/t/category-description-truncates-to-first-paragraph-for-primary-base-language-but-not-for-localizations-panel-languages/406801 In a number of places we only show the first paragraph of a category description by default, but when someone manually adds a category description translation we show the full content. This results in translated content being much longer in some places where only a single paragraph is expected (/categories pages, category headers, etc). This change cooks the translated description and applies the same single paragraph rule where relevant. `Category.first_paragraph_description` has been extracted to be used in both the default and translated descriptions so the behavior remains consistent.
-
Keegan George (10 Jul 26)
DEV: Introduce `enable_local_logins_via_code` as an alpha upcoming change (#41624) **Previously**, login with email codes was gated behind a hidden site setting, invisible to admins and checked via raw `SiteSetting` reads that would ignore upcoming-change auto-promotion. **In this update**, registered the setting as an alpha upcoming change (with preview image and learn-more link), moved server-side checks to `UpcomingChanges`, and hid the change on sites where it cannot be enabled.
-
Keegan George (10 Jul 26)
FIX: Make user field checkboxes usable on the code login page (#41626) **Previously**, required checkbox (`confirm`) user fields shown during the email-code login flow were stretched to full width by the shared `.input-group input` rule, rendering them as an unclickable bar because the checkbox size override was scoped only to `.signup-fullpage`/`.invite-page`. **In this update**, extended the override to `.login-fullpage` so checkbox user fields render at their correct size on the code login page. Added a system spec covering the scenario (required `confirm` field ā `/login` ā email code ā user-fields step), which asserts the checkbox renders at a usable width, is toggleable, and persists. Verified as a true regression test: it fails (checkbox width 404px) without the CSS change and passes with it. --------- Co-authored-by: Penar Musaraj <[email protected]>
-
Kris (10 Jul 26)
UX: update review queue icon to link (#41622) This icon got caught up in other updates, it should remain a link rather than the share icon, as it copies the link before <img width="800" alt="image" src="https://github.com/user-attachments/assets/b086070f-d7d7-436b-b939-f4aec7930ed3" /> after <img width="800" alt="image" src="https://github.com/user-attachments/assets/9c51048e-495f-4542-b93f-050684aa77cb" />
-
Gabriel Grubba (10 Jul 26)
FEATURE: Add AI agent suspend/silence tools with inline approval review (#41497) Previously, AI agents had no way to suspend or silence users, and approving any moderation tool action meant leaving the conversation for the `/review` queue. This change adds `suspend_user`/`silence_user` tools that always require moderator approval, and lets moderators approve or reject those actions from an inline review card right in the bot conversation ā credited to the approving moderator (not the bot) in the staff action log ā instead of switching to the `/review` queue. Demo of this feature: https://github.com/user-attachments/assets/b9605511-e53d-483d-b435-b212694cdf53 https://github.com/user-attachments/assets/383bda5d-93ee-4758-a51e-6162ea0d57ee --------- Co-authored-by: Penar Musaraj <[email protected]>
-
Natalie Tay (10 Jul 26)
FIX: Print site setting descriptions and setting enums correctly (#41617) For site setting descriptions, we have the ability to link to another site setting via defining `{{setting. ... }}` in the i18n description. Presentation of this was not extended to AI settings, resulting in it being poorly displayed. Also, setting enums were not being displayed properly either.
-
Penar Musaraj (10 Jul 26)
UX: Tweaks to default theme screenshots (#41592)
-
David Battersby (10 Jul 26)
FIX: close post reaction menu on route change (#41619) When the reaction menu is open and the user navigates to a new page ā we should force close the menu.
-
Joffrey JAFFEUX (10 Jul 26)
FIX: Bind workflow modal responses to their target user (#41620) Modal nodes publish an approve/reject modal to a single resolved target user over a per-user MessageBus channel. Each button carried an HMAC-signed action token, but the token only proved it was issued by the server, not who it was for: any logged-in user who obtained a valid token could POST it and resume the execution under their own account. In practice this was hard to pull off as only the valid user would get the message bus event (and the modal to show), but this is an important defense in depth fix to apply.
-
Joffrey JAFFEUX (10 Jul 26)
FEATURE: Add workflow triggers for group membership changes (#41608) Adds user_added_to_group and user_removed_from_group workflow triggers, each scoped to a required group. The triggers emit user, group, and membership metadata.
-
Alan Guo Xiang Tan (10 Jul 26)
DEV: Improve RSpec agent testing guidance (#41611) This PR updates the RSpec agent skill with Discourse-specific guidance for choosing assertions, structuring fixtures, and writing reliable system tests. The copied generic RSpec style guide duplicated upstream advice that could drift from both its source and Discourse's conventions. Key changes: * Add public-boundary and test-layer guidance so specs assert behavior owned by the layer under test. * Add fabricator, system-test cost, deterministic transient-state, URL, and page-object guidance to reduce brittle tests. * Remove the copied style guide and its references so the skill only maintains Discourse-specific advice.
-
Isaac Janzen (10 Jul 26)
SECURITY: Private UserField value disclosure via directory_items `order` sort side-channel (#41598) ## Summary Prevent unauthenticated disclosure of private user custom field values via the directory items sort order. The fix restricts the `order` parameter to public fields for non-staff users and falls back to default sorting when an unauthorized field is requested. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1334 Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com>
-
Krzysztof Kotlarek (10 Jul 26)
FIX: Return database connections to the pool after dashboard builds (#41583) Previously, AdminDashboardSectionLoader worker threads leased a database connection on their first query and held it while idling in the shared thread pool, which exhausted the connection pool (sized 5 in development) and made subsequent requests fail with "could not obtain a connection from the pool within 5.000 seconds". This change wraps each section build in ActiveRecord::Base.with_connection(prevent_permanent_checkout: true) so the connection is checked back in as soon as the section finishes building - the flag is required because sections use ActiveRecord::Base.connection internally, which would otherwise mark the connection as permanently checked out for the thread. The regression spec lives in a separate describe block with use_transactional_tests = false because both transactional tests and fab!'s before(:all) transaction pin a single shared connection across threads, which masks the leak.
-
Natalie Tay (10 Jul 26)
FEATURE: Add category scope for AI translations (#41585) We have switched AI translations settings first from public categories, to "include" categories, then to "exclude" categories. This is not great. Some admins prefer one, and some prefer others. This PR allows admins to do either. This also updates default categories to be "public" only, when the original default was "all" (public + private). The migration covers moving existing users to - if has selected categories -> "exclude strict" + their selected categories - if no selected categories + feature enabled -> "all" to maintain status quo https://github.com/user-attachments/assets/607f2340-8fa6-4059-b13d-07d1938ad74f
-
Penar Musaraj (09 Jul 26)
DEV: Fix stylesheet watcher file matching (#41593) Previously a file with `admin` in the name, would match the admin stylesheet. Now this doesn't happen. Found this out by editing the admin-onboarding-banner file and not seeing live updates in the browser.
-
Penar Musaraj (09 Jul 26)
FIX: Avoid 500 error on rare missing topic during MB publish (#41594)
-
Renato Atilio (09 Jul 26)
DEV: Clean up workflow expression reference internals (#41545) Follow-up cleanup to #41442. No behavior change. - `NODE_REF_RE` and `parseNodeReferenceName` were duplicated verbatim in `expression-context.js` and `reference-label.js`, so the two parsers had to be kept in sync by hand. They are now exported from `expression-context.js` and imported by `reference-label.js`, and the two identical single-quote unescapers in `expression-context.js` are folded into one helper. - Drops four `register_svg_icon` calls (`diagram-project`, `right-to-bracket`, `user`, `gear`) that are already in core's always-bundled base sprite (`SvgSprite::SVG_ICONS`), so re-registering them was a no-op. Only `dollar-sign` still needs registering. The other bracket/quote scanners (`splitLastAccessor`, `resolveBracketSuffix`) are deliberately left separate: they serve different purposes (runtime value resolution vs. picker-current matching) with different escaping semantics, so merging them would change behavior rather than clean it up.
-
Rafael dos Santos Silva (09 Jul 26)
FEATURE: Add 25 default data explorer queries for traffic, health, moderation and audits (#41571) Previously, the data explorer shipped only 19 default queries, mostly focused on user engagement curiosities, leaving the most common admin needs ā traffic reporting, community health trends, moderation reporting, and permission/promotion audits ā to be rediscovered over and over in Meta support topics. This change adds 25 curated default queries (ids `-20` to `-44`) covering those areas, sourced from Meta's saved query library and staff-authored answers in support topics, with stale hardcoded values generalized into parameters and known bugs fixed (overlapping histogram buckets, admin-only staff filters, row-multiplying joins replaced with `reviewable_scores`-based logic). Queries that depend on optional features (locale detection, browser pageview collection) carry an explicit warning in their description naming the required setting. Beyond being directly useful, the set is deliberately written as a learning corpus for the AI agent that helps admins create new queries (and for humans modifying them): together they demonstrate nearly every parameter type and the common patterns ā relative time windows, gapless `generate_series` series, `FILTER` aggregates, anti-joins, window functions, nullable optional filters ā with inline comments decoding non-obvious internals such as `user_histories` action codes and bot account id conventions. All 25 queries are verified to execute against a live database, and the rebuilt flag reports were smoke-tested with real flag data. --------- Co-authored-by: Natalie Tay <[email protected]>
-
Isaac Janzen (09 Jul 26)
SECURITY: detailed_404 Security Setting Bypassed (#41549) ## Summary Prevent information disclosure of topic existence by ensuring secondary topic endpoints respect the 'detailed_404' security setting. The patch implements a normalization handler for several TopicsController actionsāincluding post retrieval and notification updatesāto return a consistent 404 status code for inaccessible topics when the setting is disabled. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1384 Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com>
-
Gabriel Grubba (09 Jul 26)
FEATURE: Support bulk user search in the admin users list (#41572) Admins can now search for multiple users at once in `/admin/users/list` by separating usernames or emails with commas or whitespace ā useful for support workflows where a list of users needs to be checked in one go (e.g. pasted from a spreadsheet; spaces work because usernames and emails can never contain them). The search is also shareable via URL: typing keeps the address bar in sync with a `filter` query param (`/admin/users/list/active?filter=sam,[email protected]`), and visiting such a URL prefills the search box and filters the list. The old `username` query param keeps working as a read-only legacy fallback ā it was a misleading name, since searches also match emails. ## Demo: https://github.com/user-attachments/assets/c85e4f30-3c06-493b-9fed-bb2057209c5d
-
Kris (09 Jul 26)
UX: category slug isn't required on edit (#41570)
-
Natalie Tay (09 Jul 26)
DEV: Site settings skills - for categories can allow for more flexible options (#41504) Adding new site settings tends to involve the same small convention checks around naming, descriptions, client exposure, admin grouping, and whether the setting reads clearly in the UI. This PR adds a generic `discourse-site-settings` skill for authoring and reviewing Discourse site settings. It includes guidance for core and plugin setting files, i18n descriptions, validators for dependent settings, browser verification of rendered setting copy, and review checks. It also documents a proposed category-list pattern using paired `xyz_category_scope` and `xyz_categories` settings, including the include, exclude, strict, public, and all modes.
-
Natalie Tay (09 Jul 26)
DEV: Turn on AI data explorer queries by default (#41581) Now that we've reached a certain level of confidence for data explorer query generation using AI, we can turn it on by default.
-
Krzysztof Kotlarek (09 Jul 26)
DEV: Bump `dashboard_improvements` upcoming change to alpha (#41536) Previously, the `dashboard_improvements` upcoming change was marked as `experimental`. This change promotes it to `alpha`.
-
Mark VanLandingham (09 Jul 26)
FEATURE: Support category-scoped upcoming events calendars (#41561) Previously, embedded upcoming events calendars always fetched all visible events and created events without a category. This change lets callers pass a category scope to `UpcomingEventsCalendar`, uses it for event fetching and composer defaults, and lets embedded callers opt out of the calendar's existing route/date syncing via `@updateRouteOnDatesChange={{false}}`. The default preserves the existing `/upcoming-events` behavior for backwards compatibility.
-
Natalie Tay (09 Jul 26)
FEATURE: Scoped AI highlights to user-selected categories (#41506) AI Highlights for the dashboard now use every category. This is problematic because some categories are staff-only and shouldn't contribute to the highlights. This PR adds a new setting to scope highlights to public categories by default.
-
Alan Guo Xiang Tan (09 Jul 26)
DEV: Enable Playwright soft reset on CI for all system tests (#41573) This PR enables the Playwright soft reset optimization for every system test target on CI, not just `core` and `chat`. The soft reset path (`PlaywrightSoftReset` in `spec/support/system/capybara_patches.rb`, gated on the `CAPYBARA_PLAYWRIGHT_SOFT_RESET` env var) reuses the browser context between examples instead of tearing it down, speeding up system specs. It was previously scoped to only the `core` and `chat` targets in `.github/workflows/tests.yml` while it was proven out; the other system targets still paid the full-reset cost. Key changes: * Set `CAPYBARA_PLAYWRIGHT_SOFT_RESET` to `1` for all `system` build types, dropping the `core`/`chat` target condition, now that the approach has proven stable on those targets.
-
Martin Brennan (09 Jul 26)
DEV: Fix headings for theme setting docs (#41574) Headings are wrong levels for https://meta.discourse.org/t/add-settings-to-your-discourse-theme/82557
-
Penar Musaraj (08 Jul 26)
FIX: apply featured-links treatment to topics even when they have content (#41550) Previously, a link pasted in the title field would be treated as a featured link only if the topic had no content. With this change, this applies even if topic has content. Pasting a link in the title will assign it as a featured link and append the link to the topic content.
Discourse Security
Security Advisories (100)
- medium Patched CVSS 4.3
CVE-2026-44779 Bot debug endpoints disclose whisper translation audit logs
- medium Patched CVSS 6.5
CVE-2026-46413 Regular users can route multipart uploads into the admin backup store
- medium Patched CVSS 4.3
CVE-2026-44782 GroupPostSerializer leaks hidden full names through reaction post association
- medium Patched
CVE-2026-49256 Hidden tag names leaked via category serializers
- medium Patched CVSS 5.4
CVE-2026-44783 Replying to a whisper lets non-whisperers create staff-only whisper posts
- high Patched CVSS 7.5
CVE-2026-44786 Public chat MessageBus broadcasts are not restricted to chat-eligible users
- medium Patched CVSS 5.3
CVE-2026-45085 Chat misauthorization and information disclosure
- medium Patched CVSS 6.5
CVE-2026-44784 Non-staff group owners can see email password in plaintext through group history
- medium Patched CVSS 4.3
CVE-2026-44785 Hidden reply-to post raw can be disclosed through AI explain prompts
- high Patched CVSS 8.2
CVE-2026-44787 Signup-time primary_group_id assignment grants whisperer access
- medium Patched
CVE-2026-45788 Secure uploads exposed by hotlinked image copying
- medium Patched CVSS 5.3
CVE-2026-45780 Private event sample invitees are serialized to non-invited event viewers
- medium Patched CVSS 6.8
CVE-2026-45775 Cross-site backup access via path traversal in multisite local backups
- medium Patched CVSS 5.3
CVE-2026-59828 Hidden post revisions leak through adjacent visible diffs
- medium Patched CVSS 6.5
CVE-2026-53961 Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)
- high Patched CVSS 7.5
CVE-2026-55420 Remote code execution via pdf uploads
- medium Patched CVSS 5.4
CVE-2026-53962 Insufficient SVG sanitization logic
- high Patched
CVE-2026-55424 Topic featured link susceptible to stored XSS
- high Patched CVSS 7.3
CVE-2026-53963 Stored-XSS in 2FA delete confirmation modal
- medium Patched CVSS 5.3
CVE-2026-47264 Don't leak restricted tag group names via tag info
- low Patched
CVE-2026-34154 Subscription access bypass in discourse-subscriptions plugin
- medium Patched CVSS 4.3
CVE-2026-32951 Authorization bypass in oneboxer via user-controlled category id
- low Patched
CVE-2026-33415 Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure
- low Patched
CVE-2026-33073 discourse-subscriptions plugin leaking stripe API key in multisite environment
- medium Patched
CVE-2026-33074 Vulnerability in discourse-subscriptions plugin allowing users to self-grant to higher tier subscriptions
- medium Patched
CVE-2026-33300 Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint
- medium Patched
CVE-2026-33185 Group SMTP test endpoint susceptible to SSRF
- medium Patched
CVE-2026-33514 Information Disclosure in Form Template API Due to Missing Authorization
- medium Patched CVSS 4.3
CVE-2026-44780 Category queue reviewers can read raw incoming emails from queued posts
- low Patched
CVE-2026-34947 Staged user custom fields are exposed on public invite pages
- medium Patched CVSS 4.3
CVE-2026-47263 Prevent webhook payload disclosure on event redelivery
- medium Patched CVSS 5.3
CVE-2026-31805 Poll authorization bypass via post_id array parameter
- medium Patched
CVE-2026-31869 Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check
- medium Patched
CVE-2026-32620 Missing post-level authorization allows whisper metadata disclosure
- medium Patched
CVE-2026-32619 Insufficient topic visibility check allows unauthorized poll manipulation in private categories
- low Patched
CVE-2026-33427 Discourse Authorization Page Displays Unvalidated Redirect Domain
- medium Patched
CVE-2026-32113 Open redirect via `sso_destination_url` cookie in `enter`
- medium Patched
CVE-2026-32143 Admin-only report can be exported by moderators
- medium Patched
CVE-2026-32243 Stored XSS in discourse-ai shared conversations onebox
- medium Patched
CVE-2026-32615 Category group moderators can perform actions on topics in restricted categories without read access
- low Patched
CVE-2026-32607 Stored XSS via unescaped assignee name
- medium Patched CVSS 4.3
CVE-2026-32618 Unauthorized channel membership inference via excluded_memberships_channel_id
- medium Patched CVSS 5.4
CVE-2026-33410 Harden chat DM channel creation and expansion
- medium Patched CVSS 6.5
CVE-2026-33355 Filter whisper posts from private-posts feed
- medium Patched CVSS 4.3
CVE-2026-32099 Prevent hidden profile data leak via user onebox
- low Patched CVSS 2.7
CVE-2026-33394 Do not leak PM post edits to moderators
- medium Patched CVSS 4.3
CVE-2026-33393 Fix loose hostname matching in spam host allowlist
- medium Patched CVSS 5.3
CVE-2026-27454 Check revision visibility on posts endpoint
- medium Patched
CVE-2026-27154 XSS when editing a malicious post
- medium Patched
CVE-2026-27153 Prevent moderators from exporting user Chat DMs
- medium Patched
CVE-2026-27151 Validate destination topic when moving posts
- medium Patched
CVE-2026-27162 Prevents whispers to leak in excerpts
- medium Patched
CVE-2026-27152 DM communication-preference bypass when adding members
- medium Patched
CVE-2026-27150 Ensure guardian check when creating QueryGroupBookmark
- high Patched
CVE-2026-27149 SQL injection in PM tag filtering
- medium Patched CVSS 5.4
CVE-2026-26207 Lack of post access check in discourse-policy
- high Patched CVSS 7.5
CVE-2026-26265 IDOR vulnerability in the directory items endpoint
- medium Patched CVSS 4.3
CVE-2026-26973 Scope reviewable notes to user-visible reviewables
- low Patched CVSS 2.2
CVE-2026-33408 Improper Authorization in "Post Edits" Report For Moderators
- medium Patched CVSS 4.1
CVE-2026-27166 HTML injection via prohibited iframe URLs
- medium Patched CVSS 4.4
CVE-2026-33395 Stored clickābased XSS via Graphviz SVG javascript: links
- medium Patched
CVE-2026-27491 Bypass of official warnings messages by non-staff users
- medium Patched
CVE-2026-27021 Poll voters endpoint lacked post visibility checks
- medium Patched
CVE-2026-27481 Hidden tag visibility bypass on tag routes
- medium Patched
CVE-2026-27740 Stored XSS in AI Triage Automation
- medium Patched
CVE-2026-27570 Stored XSS via Shared AI Conversation Onebox
- medium Patched
CVE-2026-27936 Restricted post-action counts are disclosed to non-privileged users
- high Patched
CVE-2026-27934 Private topic title and post excerpt leaked via user action API endpoint
- medium Patched
CVE-2026-27935 Private topic metadata leaked to non-authorised users
- low Patched
CVE-2026-28282 Group membership addition permission bypass via discourse-policy plugin
- high Patched
CVE-2026-29072 Missing permission check for policy creation in discourse-policy
- medium Patched
CVE-2026-33291 User can create zendesk tickets even when it does not have access to topic
- medium Patched
CVE-2026-32114 Unscoped status lookups leak restricted metadata
- medium Patched CVSS 5.3
CVE-2026-32244 Cached outdated summaries can leak removed content
- medium Patched CVSS 5.4
CVE-2026-32273 XSS on category description update via API
- medium Patched
CVE-2026-33425 Private group membership or existence inferable via exclude_groups parameter
- high Patched
CVE-2026-33428 Unauthorized Access to Deleted Posts Index via Group Membership
- medium Patched
CVE-2026-30891 Unauthorized Exposure of Private User Action Types
- medium Patched
CVE-2026-30889 Unauthorized Post Data Exposure in discourse-user-notes
- medium Patched CVSS 5.4
CVE-2026-33411 Solved topic stream has potential stored XSS in topic title
- medium Patched CVSS 5.4
CVE-2026-33251 Hidden Solved topics permission bypass
- low Patched
CVE-2026-30888 Moderator privilege escalation via arbitrary post_id in suspend/silence endpoint
- medium Patched CVSS 5.9
CVE-2026-33424 PM access granted through invites after access revocation
- low Patched
CVE-2026-33423 Staff can modify any user's group notification level
- low Patched CVSS 3.5
CVE-2026-33426 Users can edit or synonymize hidden tags they can't see
- low Patched CVSS 3.5
CVE-2026-33422 ip_address of flagged user exposed
- high Patched CVSS 7.5
CVE-2026-26078 Authentication bypass vulnerability in the Patreon plugin webhook endpoint
- medium Patched
CVE-2025-68660 AI Discover's continue conversation allows to impersonate user
- medium Patched CVSS 4.3
CVE-2025-68659 DoS vulnerability in username change endpoint
- medium Patched
CVE-2025-68666 Users archives leaked to users with moderation privileges
- high Patched
CVE-2025-69218 Moderators can access admin-only reports exposing private upload URLs
- medium Patched
CVE-2025-69289 Insecure default configuration allows non-admin moderators to non-staff accounts via email change
- low Patched
CVE-2026-26979 TL4 users are able to change status of restricted topics
- medium Patched CVSS 6.5
CVE-2026-24742 Staff action logs expose sensitive information to moderators
- high Patched CVSS 7.1
CVE-2025-68479 Subscriptions are susceptible to takeover
- high Patched CVSS 7.6
CVE-2025-68662 FinalDestination hostname matching allows SSRF protection bypass
- medium Patched
CVE-2025-64528 Users are able to find users by name even when `enable_names` is off
- medium Patched
CVE-2026-23743 Permalinks to restricted resources leak resource slugs to unauthorized users
- medium Patched CVSS 6.5
CVE-2026-21865 Topic conversion permission vulnerability for moderators
- medium Patched
CVE-2026-28218 Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution
Discourse Website
Website
Discourse | Where Tech Companies Build Communities
The customizable, scalable community platform powering over 22,000 communities. Create knowledge through conversation.
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address 13.32.179.16
- Hostname server-13-32-179-16.atl59.r.cloudfront.net
- Location Atlanta, Georgia, United States of America, NA
- ISP Amazon.com Inc.
- ASN AS16509
Associated Countries
-
US -
CA
Safety Score
Website marked as safe
100%
Blacklist Check
www.discourse.org was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Discourse Reviews
More Social Networks
-
A federated, open-source link aggregator and discussion platform, similar to Reddit. Built on ActivityPub. Wide range of cross-platform client apps.
-
An open-source, distributed social media platform functioning similarly to Twitter, without algorithmic timeline manipulations. It operates across independent servers.
-
nostr stands for Notes and other stuff transmitted by relays. It is an open protocol, not merely a platform. This distinction enables truly censorship-resistant and global value-for-value publishing on the web. With the power to replace data-greedy applications like Twitter and Instagram, nostr offers a promising alternative for users seeking a more private and secure online experience without algorithmic manipulations. ".... I feel like Iām looking at the future." that is what Snowden wrote about nostr.
About the Data: Discourse
API
You can access Discourse's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/discourse The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Discourse
Help your friends compare Social Networks, and pick
privacy-respecting software and services.
Share Discourse and Awesome Privacy with your network!