← Back

CVE-2025-58054

nvd nist
Published: Oct 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed in version 3.5.1.

Affected (3)

Products: Discourse: Discourse
1 product
Discourse
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Discourse
Before 3.6.0
Before 3.5.0
Version 3.6.0 beta1

References (2)

Timeline

No history available yet.