Cross-Site Scripting Vulnerability in Discourse Discussion Platform
CVE-2026-72725
5.4MEDIUM
What is CVE-2026-72725?
Discourse, the open-source discussion platform, is subject to a stored cross-site scripting vulnerability that was introduced before version 2026.1.6. This flaw arises from the staff action log model, where unescaped previous and new field values can be exploited, allowing malicious scripts to be injected into the staff interface. This vulnerability has been addressed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0. It is crucial for users to upgrade to the fixed versions to ensure protection against potential exploits.
Affected Version(s)
discourse < 2026.1.6 < 2026.1.6
discourse >= 2026.5.0, < 2026.5.2 < 2026.5.0, 2026.5.2
discourse >= 2026.6.0, < 2026.6.1 < 2026.6.0, 2026.6.1