Cross-site scripting in Discourse - #VU140003
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the staff interface.
The vulnerability exists due to improper neutralization of input during web page generation in the staff action log rendering of previous and new value fields when rendering staff action log entries in the admin interface. A remote user can store crafted HTML or script in log values to execute arbitrary script in the staff interface.
User interaction is required for a staff user to view the affected interface.