Back

CRITICAL

Discourse BBCode plugin vulnerable to arbitrary CSS injection

Published Nov 30, 2022

Description

discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Nov 30, 2022
Updated Apr 22, 2025
Reserved Nov 28, 2022

CISA Vulnrichment

Updated Apr 22, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Nov 30, 2022
Updated Apr 22, 2025

GitHub

No data