A vulnerability was found in Discourse up to 2026.1.6/2026.6.1/2026.7.0. It has been classified as critical. Impacted is an unknown function of the file plugins/discourse-data-explorer/lib/discourse_data_explorer/data_explorer.rb of the component Data Explorer. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-72731. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability identified as problematic has been detected in Discourse up to 2026.1.5/2026.5.1/2026.6.0. The impacted element is an unknown function of the component Rich Text Editor. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-72730. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability classified as very critical was found in Dokploy up to 0.29.12. Affected by this issue is the function backup.restoreBackupWithLogs of the file packages/server/src/utils/restore/utils.ts of the component Backup Restore. The manipulation of the argument databaseName/backupFile results in os command injection.
This vulnerability was named CVE-2026-72733. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in Discourse. This affects an unknown part of the file plugins/discourse-templates/app/serializers/discourse_templates/templates_serializer.rb of the component TemplatesSerializer. This manipulation causes improper access controls.
The identification of this vulnerability is CVE-2026-72732. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Dokploy up to 0.29.12. This vulnerability affects the function server.remove of the file apps/dokploy/server/api/routers/server.ts of the component Server Removal. Such manipulation of the argument serverId leads to missing encryption of sensitive data.
This vulnerability is referenced as CVE-2026-72734. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Dokploy up to 0.29.12 and classified as critical. Impacted is the function writeTraefikConfigRemote of the file packages/server/src/utils/traefik/application.ts of the component Traefik Configuration. Executing a manipulation can lead to os command injection.
This vulnerability is tracked as CVE-2026-72735. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.