CVE-2026-72727: Discourse: Stored XSS in the moderation review queue
Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user could place crafted content in the moderation review queue that executed stored cross-site scripting when a moderator viewed it on a site with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.6 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.5.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72727?
CVE-2026-72727 has a risk rating of 41, indicating a low severity level.
How do I fix CVE-2026-72727?
To fix CVE-2026-72727, update Discourse to versions 026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.
What type of vulnerability is CVE-2026-72727?
CVE-2026-72727 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-72727?
Low-privileged users in Discourse can exploit CVE-2026-72727 by placing crafted content in the moderation review queue.
What could an attacker achieve with CVE-2026-72727?
An attacker could execute stored cross-site scripting when a moderator views the malicious content on the affected Discourse site.