CVE-2026-72731 | Discourse up to 2026.1.6/2026.6.1/2026.7.0 Data Explorer data_explorer.rb sql injection

SecurityVulns

A vulnerability was found in Discourse up to 2026.1.6/2026.6.1/2026.7.0. It has been classified as critical. Impacted is an unknown function of the file plugins/discourse-data-explorer/lib/discourse_data_explorer/data_explorer.rb of the component Data Explorer. Performing a manipulation results in sql injection.

This vulnerability is reported as CVE-2026-72731. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More