Ad

CVE-2026-27166

MEDIUM CVSS 3.1: 5.4 EPSS 0.03%
Updated Mar 25, 2026
Discourse
Parameter Value
CVSS 5.4 (MEDIUM)
Affected Versions 2026.1.0 — 2026.3.0
Fixed In 2026.3.0
Type CWE-80 (Improper Neutralization of Script-Related HTML Tags (XSS))
Vendor Discourse
Public PoC No

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2.

To workaround this issue, remove Codepen from the list of allowed iframes.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 4

Configuration From (including) Up to (excluding)
Discourse Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
2026.3.0
Discourse Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
2026.1.0 2026.1.2
Discourse Discourse
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
2026.2.0 2026.2.1
Discourse Discourse
cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:*