Nodebb

Nodebb

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 13.11.2022 14:15:10
  • Zuletzt bearbeitet 21.11.2024 07:20:39

A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of the file /register/abort. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upg...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 02.09.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:19

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later ...

  • EPSS 0.71%
  • Veröffentlicht 31.08.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:15

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially a...

Exploit
  • EPSS 2.52%
  • Veröffentlicht 29.11.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:47

Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 29.11.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:47

Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an acc...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 29.11.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:47

Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advis...

  • EPSS 0.4%
  • Veröffentlicht 20.08.2020 01:17:12
  • Zuletzt bearbeitet 21.11.2024 05:04:56

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could le...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 30.04.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 02:40:15

Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.

  • EPSS 0.34%
  • Veröffentlicht 21.09.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.