Vulnerability CVE-2022-23548


Published: 2023-01-05

Description:
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to XSS attacks. This issue is patched in versions 2.8.14 and 2.9.0.beta16. There are no known workarounds.

Type:

CWE-400

(Uncontrolled Resource Consumption ('Resource Exhaustion'))

 References:
https://github.com/discourse/discourse/pull/19737
https://github.com/discourse/discourse/security/advisories/GHSA-7rw2-f4x7-7pxf

Copyright 2026, cxsecurity.com

 

Back to Top