CVE-2026-72725
MEDIUM
5,4
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Availability
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
AI/ML, Web Based, Web Server
https://github.com/discourse/discourse/commit/66601a6e6eeeabfcb06d2f692d68534be…
https://github.com/discourse/discourse/commit/74ae22d85f4e13c7c7f2e3c13fce023fe…
https://github.com/discourse/discourse/commit/fd44510b4303e7f8f0b42bd070a2d42d3…
https://github.com/discourse/discourse/security/advisories/GHSA-8x29-vv56-wj6v