Is Discourse 3.4.7 patched?
Current stable (2026.5.0): 74/100
3.4.7 has 12 open critical-or-high vulnerabilities. Run 2026.1.4 or later to clear them. See what 2026.1.4 fixes →
Summary iPlain-English security status for Discourse 3.4.7, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Discourse 3.4.7 is part of the 3.4 release line. 56 known vulnerabilities affect it. The minimum safe version is 2026.1.4 — upgrade to it or later to clear the open critical/high issues. The 3.4 line reached end-of-life on 2025-08-19, so it no longer receives security patches. The latest supported Discourse release is 2026.5.0.
Known issues affecting 3.4.7
Exploited first, then by exploitation probability.
CVE-2021-41082 HIGH EPSS 2% → fixed in 2021-09-14 CVE-2025-48954 HIGH EPSS 1% → fixed in 3.5.0 CVE-2025-53102 CRITICAL EPSS 0% → fixed in 3.4.6 CVE-2025-48877 CRITICAL EPSS 0% → fixed in 3.5.0 CVE-2025-46813 MEDIUM EPSS 0% → fixed in 3.5.0 CVE-2026-45775 MEDIUM EPSS 0% → fixed in 2026.4.1 CVE-2025-48053 HIGH EPSS 0% → fixed in 3.5.0 CVE-2025-68662 HIGH EPSS 0% → fixed in 2025.11.2 CVE-2026-27021 MEDIUM EPSS 0% → fixed in 2026.1.1 CVE-2025-59337 MEDIUM EPSS 0% → fixed in 3.6.0 CVE-2026-24742 MEDIUM EPSS 0% → fixed in 2025.11.2 CVE-2025-61598 MEDIUM EPSS 0% → fixed in 3.6.0 CVE-2026-23743 HIGH EPSS 0% → fixed in 2025.11.2 CVE-2026-44786 HIGH EPSS 0% → fixed in 2026.4.1 CVE-2025-64528 MEDIUM EPSS 0% → fixed in 3.5.3 CVE-2026-26077 MEDIUM EPSS 0% → fixed in 2026.1.1 CVE-2026-26265 HIGH EPSS 0% → fixed in 2026.1.1 CVE-2025-68666 MEDIUM EPSS 0% → fixed in 2025.11.2 CVE-2025-68934 MEDIUM EPSS 0% → fixed in 2025.11.2 CVE-2025-58055 MEDIUM EPSS 0% → fixed in 3.6.0Other Discourse versions
Check another release line of Discourse.
Frequently asked
Is Discourse 3.4.7 patched?
Discourse 3.4.7 is end-of-life and no longer receives security patches. Move to 2026.5.0.
What version should I upgrade Discourse 3.4.7 to?
Upgrade Discourse 3.4.7 to at least 2026.1.4 to clear its 12 open critical-or-high vulnerabilities.
When does Discourse 3.4 reach end-of-life?
Discourse 3.4 reached end-of-life on 2025-08-19 and no longer receives security patches.
What is the latest version of Discourse?
The latest supported Discourse release is 2026.5.0.
Is Discourse 3.4.7 still receiving security updates?
No — Discourse 3.4.7 is on the 3.4 line, which reached end-of-life on 2025-08-19 and no longer receives security updates. Upgrade to 2026.5.0 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Discourse's official advisory before you patch or upgrade — Discourse official site ↗