Skip to main content

CVE-2022-46162

8.8
HIGHCVSS v3.1 Base Score
1.15%
LOW RiskEPSS (79th percentile)

discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.

Published: 11/30/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

1.15%LOW Exploitation Risk
79th percentile

This vulnerability has a 1.15% probability of being exploited in the next 30 days, ranking higher than 79% of all scored CVEs.

Related Vulnerabilities