Summary
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Advisory details
Impact
It's possible to forge a request to delete a message.
Patches
The problem has been patched in version 2.0-rc-1 of Discussion Extension.
Workarounds
There's no easy workaround except upgrading.
References
https://jira.xwiki.org/browse/DISCUSSION-22
For more information
If you have any questions or comments about this advisory:
- Open an issue in Jira XWiki
- Email us at security mailing-list
References
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-73222
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
- HIGHCVE-2026-73292
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
- MEDIUMCVE-2026-81890
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
- HIGHCVE-2026-19418
TYPO3 CMS - Broken Access Control in Backend and Install Tool
- MEDIUMCVE-2026-81888
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
- HIGHCVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server