CVE-2025-47288 - CVE House
Back to Database
Status published Low CVE-2025-47288

Discourse Policy plugin private group members visible

Vulnerability Description

Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there was a policy posted to a public topic that was tied to a private group then the group members could be shown to non-group members. This issue has been patched in version 0.1.1. A workaround involves moving any policy topics with private groups to restricted categories.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-47288

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

discourse-policy
Vulnerable Versions:
< 0.1.1

Timeline

Official Publish: May 29th, 2025
Last Modified: May 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)