Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-58054


Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and chat thread titles via the quote message functionality when using the rich text editor. This issue is fixed in version 3.5.1.


Published

2025-10-01T19:15:36.150

Last Modified

2025-10-23T15:09:44.777

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

Weaknesses
  • Type: Secondary
    CWE-80

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application discourse discourse < 3.5.0 Yes
Application discourse discourse < 3.6.0 Yes
Application discourse discourse 3.6.0 Yes

References