CVE-2026-53962
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in uploa
CVSS
5.4
Medio
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 9 jul 2026 · Última mod.: 14 jul 2026 · CWE-79
0.3%EPSS · 30 días0.3%
2026-07-102026-07-21
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
- github.comhttps://github.com/discourse/discourse/commit/3ee8343cd7f00d59d8513bee0a12e02d50bfc358
- github.comhttps://github.com/discourse/discourse/commit/810c2715799fd08b06fd6ffc664d9562fe9ea6ff
- github.comhttps://github.com/discourse/discourse/commit/92a699d89b84685b6fdd63cd0d0e371793c69dad
- github.comhttps://github.com/discourse/discourse/commit/b8ceb49f4ba52257be30eb3c2ce51a5bf03be5fe
- github.comhttps://github.com/discourse/discourse/releases/tag/v2026.1.5
- github.comhttps://github.com/discourse/discourse/releases/tag/v2026.4.2
- github.comhttps://github.com/discourse/discourse/releases/tag/v2026.5.1
- github.comhttps://github.com/discourse/discourse/releases/tag/v2026.6.0
- github.comhttps://github.com/discourse/discourse/security/advisories/GHSA-jmcf-3367-78vv
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-63264——
———The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.3hCVE-2026-157876.4 MED—
———The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.3hCVE-2026-164864.3 MED—
——0A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.13hCVE-2026-164854.3 MED—
——0A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.13hCVE-2026-476894.6 MED—
——0FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates using `str_replace()` without any HTML escaping. An unauthenticated attacker who knows any registered host's MAC address can POST malicious inventory values (e.g. `sysproduct`, `sysserial`) to `/service/inventory.php`, which stores them in the database. When an administrator opens the Group Inventory tab, the payload renders as executable HTML/JavaScript in the admin's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.15hCVE-2026-476877.3 ALT—
——0FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user input. An unauthenticated attacker who knows any registered host's MAC address can POST a malicious `sysproduct` value to `/service/inventory.php`, which is stored in the database. When an administrator opens Reports > Inventory, the payload breaks out of the `<option>` element and executes arbitrary JavaScript in the admin's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.15h