CVE-2025-64528

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2025.11.0:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:2025.12.0:*:*:*:stable:*:*:*

History

No history.

Information

Published : 2025-12-30 16:15

Updated : 2026-02-20 17:04


NVD link : CVE-2025-64528

Mitre link : CVE-2025-64528

CVE.ORG link : CVE-2025-64528


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-202

Exposure of Sensitive Information Through Data Queries

NVD-CWE-Other