Vulnerability Database

309,083

Total vulnerabilities in the database

CVE-2022-46148

Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the stable branch and versions 2.9.0.beta11 and prior on the beta and tests-passed branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.

  • Published: Nov 29, 2022
  • Updated: Nov 16, 2025
  • CVE: CVE-2022-46148
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.1
  • AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Software From Fixed in
discourse / discourse 2.9.0-beta1 2.9.0-beta1.x
discourse / discourse 2.9.0-beta2 2.9.0-beta2.x
discourse / discourse 2.9.0-beta3 2.9.0-beta3.x
discourse / discourse 2.9.0-beta4 2.9.0-beta4.x
discourse / discourse 2.9.0-beta5 2.9.0-beta5.x
discourse / discourse 2.9.0-beta7 2.9.0-beta7.x
discourse / discourse 2.9.0-beta8 2.9.0-beta8.x
discourse / discourse 2.9.0-beta6 2.9.0-beta6.x
discourse / discourse 2.9.0-beta10 2.9.0-beta10.x
discourse / discourse 2.9.0-beta11 2.9.0-beta11.x
discourse / discourse - 2.8.10.x