Cross-site scripting in Discourse - #VU140006
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the discourse-local-dates plugin when rendering stored content. A remote user can inject a crafted payload to execute arbitrary script in the victim's browser.
This vulnerability only affects sites that have modified or disabled the default Content Security Policy, and user interaction is required.