CVE-2025-64528

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-12-30 16:15

Updated : 2025-12-31 20:42


NVD link : CVE-2025-64528

Mitre link : CVE-2025-64528

CVE.ORG link : CVE-2025-64528


JSON object : View

Products Affected

No product.

CWE
CWE-202

Exposure of Sensitive Information Through Data Queries