CVE-2026-73038
- EPSS 0.19%
- Veröffentlicht 13.08.2026 18:41:49
- Zuletzt bearbeitet 14.08.2026 17:20:32
NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted emoji tags t...
CVE-2026-58593
- EPSS 0.21%
- Veröffentlicht 01.07.2026 19:27:23
- Zuletzt bearbeitet 07.07.2026 13:16:32
NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds...
CVE-2025-50979
- EPSS 8.14%
- Veröffentlicht 27.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 18:45:06
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and Postgre...
CVE-2025-29513
- EPSS 41.2%
- Veröffentlicht 18.04.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 01:21:40
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.
CVE-2025-29512
- EPSS 0.27%
- Veröffentlicht 18.04.2025 00:00:00
- Zuletzt bearbeitet 05.07.2026 01:21:40
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.
CVE-2024-57041
- EPSS 39.01%
- Veröffentlicht 24.01.2025 20:15:33
- Zuletzt bearbeitet 05.07.2026 01:21:15
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
CVE-2024-29316
- EPSS 0.43%
- Veröffentlicht 28.03.2024 23:15:46
- Zuletzt bearbeitet 30.06.2025 12:18:59
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.
CVE-2023-30591
- EPSS 53.8%
- Veröffentlicht 29.09.2023 06:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:28
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or objec...
CVE-2023-43187
- EPSS 45.4%
- Veröffentlicht 27.09.2023 15:19:33
- Zuletzt bearbeitet 21.11.2024 08:23:47
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.
CVE-2023-2850
- EPSS 0.33%
- Veröffentlicht 25.07.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:25
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.