CVE-2026-72725
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fie
CVSS
5.4
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 10 ago 2026 · Última mod.: 10 ago 2026 · CWE-79
Sin historial EPSS suficiente todavía.
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
- github.comhttps://github.com/discourse/discourse/commit/66601a6e6eeeabfcb06d2f692d68534be12de082
- github.comhttps://github.com/discourse/discourse/commit/74ae22d85f4e13c7c7f2e3c13fce023feec7e033
- github.comhttps://github.com/discourse/discourse/commit/fd44510b4303e7f8f0b42bd070a2d42d3cda259f
- github.comhttps://github.com/discourse/discourse/security/advisories/GHSA-8x29-vv56-wj6v
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-727435.4 MED—
———SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users viewing the dashboard.4hCVE-2026-691166.1 MED—
———FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron renderer process with access to Node.js APIs and the filesystem.5hCVE-2026-444014.8 MED—
———Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href values in Markdown links. Attackers can craft Markdown links using the javascript: scheme through ParsedownExtension.php or TwigMarkdownExtension.php, storing a persistent payload that executes in the browser of every visitor who clicks the link, enabling session cookie theft, authenticated request forgery, and credential harvesting.5hCVE-2026-727308.7 ALT—
———Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.6hCVE-2026-72729——
———Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.8hCVE-2026-72727——
———Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.8h