CVE-2026-72729: Discourse: Stored XSS in discourse-local-dates plugin
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
discourse-local-dates pluginto a version that resolves this vulnerability.Fixed in 2026.1.6 - Upgrade
Upgrade
discourse-local-dates pluginto a version that resolves this vulnerability.Fixed in 2026.5.2 - Upgrade
Upgrade
discourse-local-dates pluginto a version that resolves this vulnerability.Fixed in 2026.6.1 - Upgrade
Upgrade
discourse-local-dates pluginto a version that resolves this vulnerability.Fixed in 2026.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72729?
The severity of CVE-2026-72729 is rated as 40.
How do I fix CVE-2026-72729?
CVE-2026-72729 can be fixed by upgrading to versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 of the Discourse discourse-local-dates plugin.
What type of vulnerability is CVE-2026-72729?
CVE-2026-72729 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-72729?
Users of the Discourse platform with modified or disabled default Content Security Policy and the discourse-local-dates plugin are affected by CVE-2026-72729.
When was CVE-2026-72729 published?
CVE-2026-72729 was published on August 10, 2026.