Back to search
CVE-2025-64528
Published: Dec 30, 2025
Modified: Dec 30, 2025
PUBLISHED
Description
Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.
| Vendor | Product | Versions |
|---|---|---|
discourse | discourse | affected < 3.5.3affected >= 2025.11.0-latest, < 2025.11.1affected >= 2025.12.0-latest, < 2025.12.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now