Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nodebb HIGH 7.5
CVE-2026-58593

NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-…

Fix: after 4.13.2
Fix from $1,950 2026-07-01
Nodebb HIGH 8.6
CVE-2025-50979EPSS 8%

NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…

No fix yet
Fix from $1,950 2025-08-27
Nodebb MEDIUM 6.1
CVE-2025-29512

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the black…

Fix: after 4.0.4
Fix from $1,600 2025-04-18
Nodebb MEDIUM 6.1
CVE-2025-29513EPSS 41%

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token ge…

Fix: after 4.0.4
Fix from $1,600 2025-04-18
Nodebb MEDIUM 6.3
CVE-2024-29316

NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadm…

Mitigation only
Fix from $1,600 2024-03-28
Nodebb HIGH 7.5
CVE-2023-30591EPSS 54%

Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toSt…

Fix: after 2.8.10
Fix from $1,950 2023-09-29
Nodebb CRITICAL 9.8
CVE-2023-43187EPSS 45%

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execu…

Fix: 1.18.6+
Fix from $2,300 2023-09-27
Nodebb CRITICAL 9.8
CVE-2023-26045

NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…

Fix: 2.8.7+
Fix from $2,300 2023-07-24
Nodebb CRITICAL 9.8
CVE-2022-46164EPSS 49%

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially cr…

Fix: 2.6.1+
Fix from $2,300 2022-12-05
Nodebb HIGH 7.5
CVE-2022-36076

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional …

Fix: 1.17.2+
Fix from $1,950 2022-09-02
Nodebb CRITICAL 9.8
CVE-2022-36045

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac…

Fix: 1.19.8+
Fix from $2,300 2022-08-31
Nodebb HIGH 7.5
CVE-2021-43786

Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally al…

Fix: after 1.18.4
Fix from $1,950 2021-11-29
Nodebb MEDIUM 6.1
CVE-2021-43787

Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a mali…

Fix: after 1.18.4
Fix from $1,600 2021-11-29
Nodebb MEDIUM 5.0
CVE-2021-43788EPSS 26%

Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON…

Fix: after 1.18.4
Fix from $1,600 2021-11-29
Blog Comments HIGH 8.1
CVE-2020-15156

In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their…

Fix: 0.7.0+
Fix from $1,950 2020-08-26
Nodebb CRITICAL 9.9
CVE-2020-15149

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…

Fix: 1.14.3+
Fix from $2,300 2020-08-20
Nodebb MEDIUM 6.1
CVE-2015-9286

Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.

Fix: 0.7.3+
Fix from $1,600 2019-04-30
Nodebb MEDIUM 6.1
CVE-2015-3296

Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors re…

Fix: after 0.6.1
Fix from $1,600 2017-09-21