← Back to Versions

v3.5.3v3.5.4

Security Fixes

CVE-2025-68660

AI Discover's continue conversation allows to impersonate user

Jan 28, 2026 View details →
CVE-2025-68659

DoS vulnerability in username change endpoint

Jan 28, 2026 View details →
CVE-2025-68666

Users archives leaked to users with moderation privileges

Jan 28, 2026 View details →
CVE-2025-69218

Moderators can access admin-only reports exposing private upload URLs

Jan 28, 2026 View details →
CVE-2025-69289

Insecure default configuration allows non-admin moderators to non-staff accounts via email change

Jan 28, 2026 View details →
CVE-2026-24742

Staff action logs expose sensitive information to moderators

Jan 28, 2026 View details →
CVE-2025-68479

Subscriptions are susceptible to takeover

Jan 28, 2026 View details →
CVE-2025-68662

FinalDestination hostname matching allows SSRF protection bypass

Jan 28, 2026 View details →
CVE-2026-23743

Permalinks to restricted resources leak resource slugs to unauthorized users

Jan 28, 2026 View details →
CVE-2026-21865

Topic conversion permission vulnerability for moderators

Jan 28, 2026 View details →
CVE-2025-68933

Non-admin moderators can exfiltrate private content via post ownership transfer

Jan 28, 2026 View details →
CVE-2025-68934

Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint

Jan 28, 2026 View details →
CVE-2025-66488

Script execution in uploaded HTML/XML files on S3

Jan 28, 2026 View details →
CVE-2025-67723

Stored XSS via Katex in discourse-math plugin

Jan 28, 2026 View details →

Detailed Changes