Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-53963

37
FAUCET Score

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

First published: Jul 9, 2026Last modified: Jul 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 2026.1.0, < 2026.1.5CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
>= 2026.4.0, < 2026.4.2CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
>= 2026.5.0, < 2026.5.1CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
2026.6.0CPE matchmatch criteria
cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 36th percentile among its peer group of 265 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / discourse/discourse/commit/40de62cddadc65c328a1028ab999f3fa94adbfed
Patch
github.com / discourse/discourse/commit/529e17d4d570a48972e7cf64720e5dd1fdf23ca8
Patch
github.com / discourse/discourse/commit/d92973e51a46cf6dd20c71e6068e6769b67eea5b
Patch
github.com / discourse/discourse/commit/daea5214d833eacbdd3b1a78d99eb14e9cabd915
Patch
github.com / discourse/discourse/releases/tag/v2026.1.5
Release Notes
github.com / discourse/discourse/releases/tag/v2026.4.2
Release Notes
github.com / discourse/discourse/releases/tag/v2026.5.1
Release Notes
github.com / discourse/discourse/releases/tag/v2026.6.0
Release Notes
github.com / discourse/discourse/security/advisories/GHSA-wg5x-7f23-m3r5
MitigationVendor Advisory