You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
HTML injection in solved posts when "display name on posts" setting enabled
Low
tgxworld
published
GHSA-48h6-hpp2-357hAug 19, 2025
Package
No package listed
Affected versions
< adba4d9d6e246ea9d128a8ee4c9b673b224c2cc3
Patched versions
None
Description
Impact
User's names (not usernames) with html will may result in HTML injection when a topic is solved and the site has the display_name_on_posts setting enabled.
Impact
User's names (not usernames) with html will may result in HTML injection when a topic is solved and the site has the
display_name_on_posts
setting enabled.Workarounds
Disable the
display_name_on_posts
setting.