CVE-2023-30611: Discourse Reactions
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
Affected products
- Discourse Reactions: version 0.2 only
Published 2023-04-19. Last modified 2026-06-17.