This repository was archived by the owner on Jul 15, 2025. It is now read-only.
Improper escaping of user input can lead to XSS under non-default site configuration
Package
discourse-calendar
(Discourse)
Affected versions
<= 9d1726fe
Patched versions
> 9d1726fe
Impact
Improper escaping of event titles could lead to XSS within the 'email preview' UI when a site has CSP disabled. Having CSP disabled is a non-default configuration, so the vast majority of sites are unaffected.
Patches
This problem is resolved in the latest version of the discourse-calendar plugin
Workarounds
Ensure CSP is enabled on the forum.