5.4
CVE-2026-53962
- EPSS 0.3%
- Veröffentlicht 09.07.2026 22:02:27
- Zuletzt bearbeitet 14.07.2026 01:35:33
- CVE-Watchlists
- Unerledigt
Discourse: Insufficient SVG sanitization logic
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripting when a user visited specific URLs that are not normally part of community browsing. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.222 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/discourse/discourse/releases/tag/v2026.1.5
https://github.com/discourse/discourse/releases/tag/v2026.4.2
https://github.com/discourse/discourse/releases/tag/v2026.5.1
https://github.com/discourse/discourse/releases/tag/v2026.6.0
https://github.com/discourse/discourse/security/advisories/GHSA-jmcf-3367-78vv
https://github.com/discourse/discourse/commit/3ee8343cd7f00d59d8513bee0a12e02d50bfc358
https://github.com/discourse/discourse/commit/810c2715799fd08b06fd6ffc664d9562fe9ea6ff
https://github.com/discourse/discourse/commit/92a699d89b84685b6fdd63cd0d0e371793c69dad
https://github.com/discourse/discourse/commit/b8ceb49f4ba52257be30eb3c2ce51a5bf03be5fe