CVE-2026-72720 | Discourse Email Formatting PrettyText.format_for_email cooked cross site scripting
A vulnerability marked as problematic has been reported in Discourse. Impacted is the function PrettyText.format_for_email of the component Email Formatting. The manipulation of the argument cooked leads to cross site scripting.
This vulnerability is referenced as CVE-2026-72720. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More