What is CVE-2026-53960?
CVE-2026-53960 in Discourse exposes hidden or unviewable first-post content via publicly-served Q&A JSON-LD structured data, leaking it to unauthenticated visitors and search engines. Affected versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 require immediate patching.
Azərbaycanca: Discourse platformasında aşkarlanan CVE-2026-53960 zəifliyi, gizli və ya ilk baxışda görünməyən ilk mesaj məzmununun Q&A JSON-LD strukturlaşdırılmış məlumatlar vasitəsilə ictimaiyyətə sızmasına səbəb olur. Bu, autentifikasiya olunmamış ziyarətçilərin və axtarış motorlarının məxfi məlumatları əldə etməsinə yol aça bilər. Platforma 2026.1.6, 2026.5.2, 2026.6.1 və 2026.7.0 versiyalarına qədər yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What confidential information does CVE-2026-53960 expose in the Discourse platform?
This vulnerability leaks hidden or unviewable first-post content via publicly-served Q&A JSON-LD structured data.
To which versions should Discourse be updated to remediate this vulnerability?
The platform must be updated to versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.