๐Ÿ” CVE Alert

CVE-2026-72729

UNKNOWN 0.0

Discourse: Stored XSS in discourse-local-dates plugin

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

CWE CWE-79
Vendor discourse
Product discourse
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for discourse discourse

Be the first to know when new unknown vulnerabilities affecting discourse discourse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

discourse / discourse
< 2026.1.6 >= 2026.5.0-latest, < 2026.5.2 >= 2026.6.0-latest, < 2026.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/discourse/discourse/security/advisories/GHSA-rw96-2xg7-h54g github.com: https://github.com/discourse/discourse/commit/9768f476ed86ea202440cd2b6245af8a4f94ec69 github.com: https://github.com/discourse/discourse/commit/981ba23d33d2e2d98f6690734116af58f2cea938 github.com: https://github.com/discourse/discourse/commit/a7e509bfa1aa6288b447503de6ef798c31a62751 github.com: https://github.com/discourse/discourse/commit/d5d5055fbdf04d5bd72fcaa7e4257fac5adac049