Description
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Published: 2026-08-10
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Discourse is an open‑source discussion platform. Prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse‑local‑dates plugin rendered crafted local‑date format data as HTML on sites with a modified or disabled default Content Security Policy. This flaw allows an attacker to inject malicious scripts that execute in the context of users who view the rendered content, constituting a stored XSS vulnerability.

Affected Systems

Discourse (open‑source discussion platform) running the discourse‑local‑dates plugin is affected. Versions on or before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are vulnerable.

Risk and Exploitability

The CVSS score of 2.0 reflects low severity. With no EPSS score available and no entry in KEV, the risk of exploitation appears limited. However, the flaw can be exploited if a site’s default CSP has been altered or disabled, allowing the injected HTML to run. Attackers could inject malicious scripts that trigger when a victim views content containing the vulnerable date format.

Generated by OpenCVE AI on August 10, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the patched releases (2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0) where the flaw is fixed.
  • If immediate upgrade is not possible, enforce a strict Content Security Policy that disallows inline scripts and blocks the plugin’s ability to render raw HTML.
  • Audit the discourse‑local‑dates plugin configuration, remove any custom formatting that permits rendering of raw HTML, and disable or replace the plugin if it is no longer needed.

Generated by OpenCVE AI on August 10, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Discourse
Discourse discourse
Vendors & Products Discourse
Discourse discourse

Tue, 11 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Title Discourse: Stored XSS in discourse-local-dates plugin
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Discourse Discourse
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-11T01:58:54.504Z

Reserved: 2026-08-10T13:48:09.545Z

Link: CVE-2026-72729

cve-icon Vulnrichment

Updated: 2026-08-11T01:58:50.383Z

cve-icon NVD

Status : Received

Published: 2026-08-10T17:17:37.337

Modified: 2026-08-11T03:18:01.673

Link: CVE-2026-72729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T05:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')