CVE-2026-72730 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 Rich Text Editor cross site scripting

SecurityVulns

A vulnerability identified as problematic has been detected in Discourse up to 2026.1.5/2026.5.1/2026.6.0. The impacted element is an unknown function of the component Rich Text Editor. This manipulation causes cross site scripting.

This vulnerability appears as CVE-2026-72730. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More