CVE Feed

    Dashboard / CVE / CVE-2022-46162

    CVE-2022-46162

    discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.

    Published:Nov 30, 2022
    Last Modified:Apr 22, 2025
    EPS:Nov 30, 2022
    EPSS Score:0.00471
    CVSS Score:8.8

    Affected Products

    Vendor
    Discourse
    Product
    Discourse Bbcode

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High