GHSA-4j38-rw27-97gxMediumCVSS 6.5

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

Published
July 27, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

It's possible to forge a request to delete a message.

Patches

The problem has been patched in version 2.0-rc-1 of Discussion Extension.

Workarounds

There's no easy workaround except upgrading.

References

https://jira.xwiki.org/browse/DISCUSSION-22

For more information

If you have any questions or comments about this advisory:

🎯 Affected products1

  • maven/org.xwiki.contrib:discussions-server:< 2.0-rc-1

🔗 References (3)