Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-58593 NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-… Nodebb after 4.13.2 Fix from $1,9502026-07-01 HIGH 8.6 CVE-2025-50979EPSS 8% NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro… Nodebb No fix yet Fix from $1,9502025-08-27 MEDIUM 6.1 CVE-2025-29512 Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the black… Nodebb after 4.0.4 Fix from $1,6002025-04-18 MEDIUM 6.1 CVE-2025-29513EPSS 41% Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token ge… Nodebb after 4.0.4 Fix from $1,6002025-04-18 MEDIUM 6.3 CVE-2024-29316 NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadm… Nodebb Mitigation only Fix from $1,6002024-03-28 HIGH 7.5 CVE-2023-30591EPSS 54% Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toSt… Nodebb after 2.8.10 Fix from $1,9502023-09-29 CRITICAL 9.8 CVE-2023-43187EPSS 45% A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execu… Nodebb 1.18.6+ Fix from $2,3002023-09-27 CRITICAL 9.8 CVE-2023-26045 NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s… Nodebb 2.8.7+ Fix from $2,3002023-07-24 CRITICAL 9.8 CVE-2022-46164EPSS 49% NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially cr… Nodebb 2.6.1+ Fix from $2,3002022-12-05 HIGH 7.5 CVE-2022-36076 NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional … Nodebb 1.17.2+ Fix from $1,9502022-09-02 CRITICAL 9.8 CVE-2022-36045 NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac… Nodebb 1.19.8+ Fix from $2,3002022-08-31 HIGH 7.5 CVE-2021-43786 Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally al… Nodebb after 1.18.4 Fix from $1,9502021-11-29 MEDIUM 6.1 CVE-2021-43787 Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a mali… Nodebb after 1.18.4 Fix from $1,6002021-11-29 MEDIUM 5.0 CVE-2021-43788EPSS 26% Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON… Nodebb after 1.18.4 Fix from $1,6002021-11-29 HIGH 8.1 CVE-2020-15156 In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their… Blog Comments 0.7.0+ Fix from $1,9502020-08-26 CRITICAL 9.9 CVE-2020-15149 NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user… Nodebb 1.14.3+ Fix from $2,3002020-08-20 MEDIUM 6.1 CVE-2015-9286 Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS. Nodebb 0.7.3+ Fix from $1,6002019-04-30 MEDIUM 6.1 CVE-2015-3296 Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors re… Nodebb after 0.6.1 Fix from $1,6002017-09-21