Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*
- >= 0
- >= 2025.11.0-latest
- >= 2025.12.0-latest
- >= 2026.1.0-latest
A cross-site scripting vulnerability has been identified in the Discourse Math plugin, specifically in its KaTeX variant. This issue is present in Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. The vulnerability is mitigated by the content security policy, but it still allows for stored cross-site scripting.
Exploitation of this vulnerability allows for stored cross-site scripting, where malicious scripts can be injected and executed.
Users can update to Discourse versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0. Alternatively, the Discourse Math plugin can be disabled or the Mathjax provider can be used instead of KaTeX.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.