← Back to Versions

v2026.1.0v2026.1.1

Security Fixes

CVE-2026-27154

XSS when editing a malicious post

Feb 26, 2026 View details →
CVE-2026-27153

Prevent moderators from exporting user Chat DMs

Feb 26, 2026 View details →
CVE-2026-27151

Validate destination topic when moving posts

Feb 26, 2026 View details →
CVE-2026-27162

Prevents whispers to leak in excerpts

Feb 26, 2026 View details →
CVE-2026-27152

DM communication-preference bypass when adding members

Feb 26, 2026 View details →
CVE-2026-27150

Ensure guardian check when creating QueryGroupBookmark

Feb 26, 2026 View details →
CVE-2026-27149

SQL injection in PM tag filtering

Feb 26, 2026 View details →
CVE-2026-26207

Lack of post access check in discourse-policy

Feb 26, 2026 View details →
CVE-2026-26265

IDOR vulnerability in the directory items endpoint

Feb 26, 2026 View details →
CVE-2026-26973

Scope reviewable notes to user-visible reviewables

Feb 26, 2026 View details →
CVE-2026-27021

Poll voters endpoint lacked post visibility checks

Feb 26, 2026 View details →
CVE-2026-26078

Authentication bypass vulnerability in the Patreon plugin webhook endpoint

Feb 26, 2026 View details →
CVE-2026-26979

TL4 users are able to change status of restricted topics

Feb 26, 2026 View details →
CVE-2026-28218

Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution

Feb 26, 2026 View details →
CVE-2026-26077

Ensures webhooks require a token

Feb 26, 2026 View details →
CVE-2026-28227

Unauthorized Topic Creation in Staff-Only Categories via Topic Timer publish_to_category

Feb 26, 2026 View details →
CVE-2026-28219

Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Banners

Feb 26, 2026 View details →

Detailed Changes