Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post Edits admin report (/admin/reports/post_edits) leaked the first 40 characters of raw post content from private messages and secure categories to moderators who shouldn't have access. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
We have discovered 884 live websites that are affected by CVE-2026-33394.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 884 live websites (20% of Discourse install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 3 versions ( 4.23% of all versions) |
| 481 websites | |
| 193 websites | |
| 39 websites | |
| 25 websites | |
| 18 websites | |
| 14 websites | |
| 14 websites | |
| 11 websites | |
| 10 websites | |
| 9 websites |
| .com | 389 websites |
| .org | 125 websites |
| .net | 44 websites |
| .io | 30 websites |
| .de | 29 websites |
| .fr | 15 websites |
| .co.uk | 13 websites |
| .ch | 11 websites |
| .eu | 10 websites |
| .nl | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | **,*** | ||
| *********.***********.com | **,*** | ||
| ***********.com | ***,*** | ||
| *****.********.com | ***,*** | ||
| *********.*******.org | ***,*** | ||
| *********.de | ***,*** | ||
| ****.***********.org | ***,*** | ||
| *****.********.com | ***,*** | ||
| *******.****.org | ***,*** | ||
| ******.************.net | ***,*** |
FAQ