CVE-2025-67723

Discourse vulnerable to stored Cross-site Scripting via Katex in discourse-math plugin

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a content-security-policy-mitigated cross-site scriptinv vulnerability on the Discourse Math plugin when using its KaTeX variant. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, the Discourse Math plugin can be disabled, or the Mathjax provider can be used instead of KaTeX.


We have discovered 3,232 live websites that are affected by CVE-2025-67723.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains3,232 live websites (71% of Discourse install base)
Vulnerable Versions
  • from 0 through 3.5.4
  • from 2025.11 through 2025.11.2
  • from 2025.12 through 2025.12.1
  • from 2026.1 through 2026.1
Vulnerable Versions Count64 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 28, 2026
  • Updated - Jan 28, 2026

Website Distribution by Country

Number of websites using CVE-2025-67723
United States1,968 websites



Germany521 websites
France134 websites
Singapore76 websites
GB59 websites
China45 websites
Russia44 websites
Netherlands32 websites
Switzerland29 websites
Canada25 websites

Website Distribution by TLD

Number of websites using CVE-2025-67723
.com1,383 websites
.org576 websites
.net165 websites
.io147 websites
.de86 websites
.ru35 websites
.fr34 websites
.eu29 websites
.co27 websites
.nl23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67723

Top websites that are affected by CVE-2025-67723. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
*********.**********.com United States*,***
*****.******.org Germany*,***
*****.******.com United States*,***
*********.***********.org United States**,***
*********.**********.com United States**,***
*********.******.com Germany**,***
*******.******.com United States**,***
*********.*******.com United States**,***
******************.com United States**,***
See full domain list

FAQ

CVE-2025-67723 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Discourse
A total of 3,232 websites have been identified as vulnerable to CVE-2025-67723, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2025-67723 vulnerability.
Discourse versions up to 2026.1 are vulnerable to CVE-2025-67723.
CVE-2025-67723 is resolved in version 2026.1 of Discourse.