Vulnerability Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/discourse/discourse/commit/66601a6e6eeeabfcb06d2f692d68534be1
- https://github.com/discourse/discourse/commit/74ae22d85f4e13c7c7f2e3c13fce023fee
- https://github.com/discourse/discourse/commit/fd44510b4303e7f8f0b42bd070a2d42d3c
- https://github.com/discourse/discourse/security/advisories/GHSA-8x29-vv56-wj6v
FAQ
What is CVE-2026-72725?
CVE-2026-72725 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the s...
How severe is CVE-2026-72725?
CVE-2026-72725 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72725?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.