← Back to Versions

v2026.1.1v2026.1.2

Security Fixes

Harden chat DM channel creation and expansion

Mar 19, 2026 View details →

Filter whisper posts from private-posts feed

Mar 19, 2026 View details →
CVE-2026-32099

Prevent hidden profile data leak via user onebox

Mar 19, 2026 View details →

Do not leak PM post edits to moderators

Mar 19, 2026 View details →

Fix loose hostname matching in spam host allowlist

Mar 19, 2026 View details →
CVE-2026-27454

Check revision visibility on posts endpoint

Mar 19, 2026 View details →

Improper Authorization in "Post Edits" Report For Moderators

Mar 19, 2026 View details →
CVE-2026-27166

HTML injection via prohibited iframe URLs

Mar 19, 2026 View details →

Stored click‑based XSS via Graphviz SVG javascript: links

Mar 19, 2026 View details →
CVE-2026-27491

Bypass of official warnings messages by non-staff users

Mar 19, 2026 View details →
CVE-2026-27740

Stored XSS in AI Triage Automation

Mar 19, 2026 View details →
CVE-2026-27570

Stored XSS via Shared AI Conversation Onebox

Mar 19, 2026 View details →
CVE-2026-27936

Restricted post-action counts are disclosed to non-privileged users

Mar 19, 2026 View details →
CVE-2026-27934

Private topic title and post excerpt leaked via user action API endpoint

Mar 19, 2026 View details →
CVE-2026-27935

Private topic metadata leaked to non-authorised users

Mar 19, 2026 View details →
CVE-2026-28282

Group membership addition permission bypass via discourse-policy plugin

Mar 19, 2026 View details →
CVE-2026-29072

Missing permission check for policy creation in discourse-policy

Mar 19, 2026 View details →

Detailed Changes