Vulnerability Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/discourse/discourse/commit/32920affe4ad97b461ca2ae2f664c5fefc
- https://github.com/discourse/discourse/commit/3fb1e8ead0d4f48d2cf55c8110825c7e8a
- https://github.com/discourse/discourse/commit/7eb35d076ab9b6a612e86182336ce9787c
- https://github.com/discourse/discourse/commit/9633b8ecaf5a99f0407f5261b9bd1a05f7
- https://github.com/discourse/discourse/security/advisories/GHSA-wg48-qxjc-f459
FAQ
What is CVE-2026-72730?
CVE-2026-72730 is a vulnerability with a CVSS score of 8.7 (HIGH). Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scrip...
How severe is CVE-2026-72730?
CVE-2026-72730 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72730?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.