216.73.216.233

CVE-2026-32273

· Published 31/03/2026 18:16 · Modified 01/04/2026 14:24

Labels: CVE-2026-32273 2026-03-31CVE-2026-32273CWE-79[email protected]

Essential information

Published
31/03/2026 18:16
Modified
01/04/2026 14:24
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
discourse / discourse cpe:2.3:a:discourse:discourse:2026.1.0-2026.1.3:*:*:*:*:*:*:*
discourse / discourse cpe:2.3:a:discourse:discourse:2026.2.0-2026.2.2:*:*:*:*:*:*:*
discourse / discourse cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:*:*:*:*

References