9

CVE-2026-53963

Discourse: Stored-XSS in 2FA delete confirmation modal

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DiscourseDiscourse Version >= 2026.1.0 < 2026.1.5
DiscourseDiscourse Version >= 2026.4.0 < 2026.4.2
DiscourseDiscourse Version >= 2026.5.0 < 2026.5.1
DiscourseDiscourse Version2026.6.0 SwEditionlatest
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.399
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 2.3 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
security-advisories@github.com 7.3 2.1 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/discourse/discourse/releases/tag/v2026.1.5
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.4.2
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.5.1
Release Notes
https://github.com/discourse/discourse/releases/tag/v2026.6.0
Release Notes
https://github.com/discourse/discourse/security/advisories/GHSA-wg5x-7f23-m3r5
Vendor Advisory
Mitigation
https://github.com/discourse/discourse/commit/40de62cddadc65c328a1028ab999f3fa94adbfed
Patch
https://github.com/discourse/discourse/commit/529e17d4d570a48972e7cf64720e5dd1fdf23ca8
Patch
https://github.com/discourse/discourse/commit/d92973e51a46cf6dd20c71e6068e6769b67eea5b
Patch
https://github.com/discourse/discourse/commit/daea5214d833eacbdd3b1a78d99eb14e9cabd915
Patch