CVE-2026-72725: Discourse: Stored XSS in staff action logs injects staff UI
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the staff interface. The issue is fixed in 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.6 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.5.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72725?
The severity of CVE-2026-72725 is medium with a CVSS score of 5.4.
How do I fix CVE-2026-72725?
To fix CVE-2026-72725, update Discourse to version 2026.1.6 or later.
What type of vulnerability is CVE-2026-72725?
CVE-2026-72725 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-72725?
CVE-2026-72725 affects users of Discourse versions prior to 2026.1.6.
What are the potential impacts of CVE-2026-72725?
The potential impacts of CVE-2026-72725 include the injection of malicious scripts into the staff interface.