PT-2024-35446 · Discourse · Discourse

Pmusaraj

·

Published

2024-12-19

·

Updated

2025-08-26

·

CVE-2024-52794

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Discourse versions prior to the latest version
Description Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. The issue is resolved in the latest version of Discourse.
Recommendations Upgrade to the latest version of Discourse to resolve the issue. As a temporary workaround, consider avoiding the use of lightbox thumbnails until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2024-52794
CVE-2024-52794
GHSA-M3V4-V2RP-HFM9

Affected Products

Discourse