Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.logged_in_members site text to remove the preferred_display_name placeholder, or not impersonate
any users for the time being. This vulnerability is fixed in 3.5.0.beta8.
References
| Link | Resource |
|---|---|
| https://github.com/discourse/discourse/commit/a3374d2850f07444d113216e1d539ee21650dbff | Patch |
| https://github.com/discourse/discourse/security/advisories/GHSA-5mm6-j5vq-6884 | Mitigation Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2026, 09:40
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Discourse discourse
Discourse |
|
| CPE | cpe:2.3:a:discourse:discourse:3.5.0:beta1:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.5.0:beta5:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.5.0:beta7:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.5.0:beta6:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:*:*:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.5.0:beta4:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.5.0:beta2:*:*:beta:*:*:* cpe:2.3:a:discourse:discourse:3.5.0:beta3:*:*:beta:*:*:* |
|
| References | () https://github.com/discourse/discourse/commit/a3374d2850f07444d113216e1d539ee21650dbff - Patch | |
| References | () https://github.com/discourse/discourse/security/advisories/GHSA-5mm6-j5vq-6884 - Mitigation, Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
20 Aug 2025, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
19 Aug 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-19 17:15
Updated : 2026-06-17 09:40
NVD link : CVE-2025-54411
Mitre link : CVE-2025-54411
CVE.ORG link : CVE-2025-54411
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
