{"id":"CVE-2026-72730","title":"Discourse is an open-source discussion platform","summary":"Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-79"],"published":"2026-08-10","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:54:37.790","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72730","references":[{"url":"https://github.com/discourse/discourse/commit/32920affe4ad97b461ca2ae2f664c5fefc374baf","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/commit/3fb1e8ead0d4f48d2cf55c8110825c7e8a6a45f5","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/commit/7eb35d076ab9b6a612e86182336ce9787ce402ea","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/commit/9633b8ecaf5a99f0407f5261b9bd1a05f7dac529","label":"security-advisories@github.com"},{"url":"https://github.com/discourse/discourse/security/advisories/GHSA-wg48-qxjc-f459","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00236,"epssPercentile":0.14934,"ingestedAt":"2026-09-08T21:11:12.273Z","slug":"CVE-2026-72730","body":"## Overview\n\nDiscourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scripting. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}