VYPR
Medium severity5.4NVD Advisory· Published Aug 10, 2026· Updated Aug 10, 2026

CVE-2026-72725

CVE-2026-72725

Description

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.