CVE-2025-48954
Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting wh
Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue.
As a workaround, have the content security policy enabled.
HIGH · CVSS 8.1
EPSS 0.10124
Act now
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0