🚨 CVE-2026-72730
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
🎖@cveNotify
GitHub
SECURITY: Stored XSS chat-transcript username unescaped in Rich Text … · discourse/discourse@32920af
…Editor [backport 2026.6]
September 8, 2026 3