2.4
/ 10
LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.logged_in_members site text to remove the preferred_display_name placeholder, or not impersonate
any users for the time being. This vulnerability is fixed in 3.5.0.beta8.
any users for the time being. This vulnerability is fixed in 3.5.0.beta8.
Basic Information
ID
CVE-2025-54411
Source
GitHub_M
Published
Aug 19, 2025 at 16:41
Affected Product
Vendor
discourse
Product
discourse
Version
< 3.5.0.beta8
Affected Versions
discourse discourse < 3.5.0.beta8