Sploitus

CVE-2024-53266

No indexed exploits for CVE-2024-53266 yet

Discourse is an open source platform for community discussion. In affected versions with some combinations of plugins, and with CSP disabled, activity streams in the user's profile page may be vulnerable to XSS. This has been patched in the latest version of Discourse core. Users are advised to upgrade. Users unable to upgrade should ensure CSP is enabled.

Affected products
Discourse
Discourse
< 3.3.3, 3.4.0
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.3% (19th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2025-02-04
CVE-2024-53266 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-53266 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-53266 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.