PT-2026-57000 · Discourse · Discourse
CVE-2026-53963
·
Published
2026-07-09
·
Updated
2026-07-15
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Discourse versions prior to 2026.6.0
Discourse versions prior to 2026.5.1
Discourse versions prior to 2026.4.2
Discourse versions prior to 2026.1.5
Description
A stored cross-site scripting issue exists where a malicious second factor name on an account controlled by an attacker is not properly escaped in the delete confirmation dialog. This allows the execution of arbitrary scripts when an administrator impersonates the affected account.
Recommendations
Update to version 2026.6.0
Update to version 2026.5.1
Update to version 2026.4.2
Update to version 2026.1.5
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discourse