Medium severity6.1NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-45303
CVE-2024-45303
Description
Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rendering event names can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content Security Policy. The issue is patched in version 0.5 of the Discourse Calendar plugin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<0.5+ 1 more
- (no CPE)range: <0.5
- (no CPE)range: < 0.5
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.