HomeDiscourseCVE-2025-58054

CVE-2025-58054

LOW
3.5CVSS
Published: 2025-10-01
Updated: 2025-10-23
AI Analysis

Description

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed in version 3.5.1.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-80

Metadata

Primary Vendor
DISCOURSE
Published
10/1/2025
Last Modified
10/23/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

discourse : discoursediscourse : discoursediscourse : discourse

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-58054 | LOW Severity | CVEDatabase.com | CVEDatabase.com