Home/Product/nodebb
Product

nodebb

20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-50979
all versions
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query p
8.6HIGH
CVE-2025-29513
<= 4.0.4
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin
6.1MEDIUM
CVE-2025-29512
<= 4.0.4
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potential
6.1MEDIUM
CVE-2024-57041
all versions
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'ab
4.6MEDIUM
CVE-2024-29316
all versions
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Adm
6.3MEDIUM
CVE-2023-30591
<= 2.8.10
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking eventName.startsWith()
7.5HIGH
CVE-2023-43187
< 1.18.6
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows
9.8CRITICAL
CVE-2023-2850
< 2.8.13
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation
4.7MEDIUM
CVE-2023-26045
>= 2.5.0 and < 2.8.7
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destruc
10.0CRITICAL
CVE-2022-46164
< 2.6.1
NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message hand
9.4CRITICAL
CVE-2022-3978
< 2.5.8
A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of the file /r
4.3MEDIUM
CVE-2022-36076
< 1.17.2
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily
8.8HIGH
CVE-2022-36045
< 1.19.8
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets
9.0CRITICAL
CVE-2021-43788
>= 1.0.4 and <= 1.18.4
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed u
5.0MEDIUM
CVE-2021-43787
>= 1.15.5 and <= 1.18.4
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader mo
9.0CRITICAL
CVE-2021-43786
>= 1.15.0 and <= 1.18.4
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step
9.8CRITICAL
CVE-2020-15156
< 0.7.0
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third par
6.8MEDIUM
CVE-2020-15149
>= 1.12.2 and < 1.14.3
NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the p
9.9CRITICAL
CVE-2015-9286
< 0.7.3
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
6.1MEDIUM
CVE-2015-3296
<= 0.6.1
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or
6.1MEDIUM
threatengine.sh