Local Date Format Rendering Vulnerability in Discourse Discussion Platform
CVE-2026-72729

2LOW

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72729?

The discourse-local-dates plugin in Discourse, an open-source discussion platform, is susceptible to a rendering flaw. When the default Content Security Policy (CSP) is either modified or disabled, the plugin can present specially crafted local-date format data as HTML, potentially compromising site security. This vulnerability has been rectified in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, highlighting the importance of maintaining updated versions to safeguard against such risks.

Affected Version(s)

discourse < 2026.1.6 < 2026.1.6

discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2

discourse >= 2026.6.0-latest, < 2026.6.1 < 2026.6.0-latest, 2026.6.1

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.