# 3.1.5: Security and bug fix release

**URL:** https://meta.discourse.org/t/3-1-5-security-and-bug-fix-release/293094
**Category:** Announcements
**Tags:** release-notes
**Created:** [January 30, 2024, 7:55pm UTC](https://meta.discourse.org/t/3-1-5-security-and-bug-fix-release/293094 "2024-01-30T19:55:22Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [January 30, 2024, 7:55pm UTC](https://meta.discourse.org/t/3-1-5-security-and-bug-fix-release/293094/1 "2024-01-30T19:55:22Z")

</div>

## Discourse 3.1.5 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

## Security Updates

This release includes fixes for this security issue reported by our community and [HackerOne](https://hackerone.com/discourse).

- Improperly sanitized user input leads to XSS [(CVE-2024-23834)](https://github.com/discourse/discourse/security/advisories/GHSA-rj3g-8q6p-63pc)

---

_[View the full topic](https://meta.discourse.org/t/3-1-5-security-and-bug-fix-release/293094)._
