CVE-2026-32273
Discourse: XSS on category description update via API
5.4
MEDIUM
CVSS 3.1
EPSS 0.04%
Description
Discourse is an open-source discussion platform. From versions 2026.1.0 to before 2026.1.3, and 2026.2.0 to before 2026.2.2, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
How to fix CVE-2026-32273
To remediate CVE-2026-32273, upgrade the affected package to a fixed version below.
- —upgrade to 2026.1.3 or later
Is CVE-2026-32273 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2026.1.0, < 2026.1.3, >= 2026.2.0, < 2026.2.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |