Impact
Discourse is an open‑source discussion platform. Prior to versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse‑local‑dates plugin rendered crafted local‑date format data as HTML on sites with a modified or disabled default Content Security Policy. This flaw allows an attacker to inject malicious scripts that execute in the context of users who view the rendered content, constituting a stored XSS vulnerability.
Affected Systems
Discourse (open‑source discussion platform) running the discourse‑local‑dates plugin is affected. Versions on or before 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are vulnerable.
Risk and Exploitability
The CVSS score of 2.0 reflects low severity. With no EPSS score available and no entry in KEV, the risk of exploitation appears limited. However, the flaw can be exploited if a site’s default CSP has been altered or disabled, allowing the injected HTML to run. Attackers could inject malicious scripts that trigger when a victim views content containing the vulnerable date format.
OpenCVE Enrichment