PT-2025-33751 · Discourse · Discourse

Tgxworld

·

Published

2025-08-19

·

Updated

2025-08-21

·

CVE-2025-54411

CVSS v4.0

2.4

Low

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Discourse versions prior to 3.5.0.beta8
Description: Discourse, an open-source discussion platform, contains a cross-site scripting (XSS) issue in the welcome banner user name string for logged-in users. This can affect the user or an administrator impersonating them.
Recommendations: Update to version 3.5.0.beta8 or later. As a temporary workaround, administrators can alter the welcome banner.header.logged in members site text to remove the preferred display name placeholder. Administrators can avoid impersonating any users for the time being.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DISCOURSE-2025-54411
CVE-2025-54411
GHSA-5MM6-J5VQ-6884

Affected Products

Discourse