
CVE-2026-27154 Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name can be evaluated as raw HTML when the following… https://www.cve.org/CVERecord?id=CVE-2026-27154
Post summary
The post reports a CVE affecting Discourse where user full names can be rendered as raw HTML and notes that newer versions (2025.12.2, 2026.1.1, 2026.2.0) contain the patch.

