nodebb records
21 published records for vendor nodebb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-330 Use of Insufficiently Random Values1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2022-46164Proof of concept | Account takeover via prototype vulnerabilitynodebb · nodebb · CWE-665 | Critical9.8 | — | 49.0% | Dec 5, 2022 |
53Plan | CVE-2023-43187Proof of concept | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackersnodebb · nodebb · CWE-91 | Critical9.8 | — | 46.9% | Sep 27, 2023 |
46Plan | CVE-2023-30591No exploit | NodeBB Pre-Authentication Denial-of-Servicenodebb · nodebb · CWE-241 | High7.5 | — | 53.8% | Sep 29, 2023 |
40Plan | CVE-2020-15149No exploit | Account takeover in NodeBBnodebb · nodebb · CWE-269 | Critical9.9 | — | 2.4% | Aug 19, 2020 |
39Monitor | CVE-2022-36045No exploit | Account takeover via cryptographically weak PRNG in NodeBB Forumnodebb · nodebb · CWE-330 | Critical9.8 | — | 1.3% | Aug 31, 2022 |
39Monitor | CVE-2023-26045No exploit | NodeBB vulnerable to path traversal and code execution via prototype vulnerabilitynodebb · nodebb · CWE-22 | Critical9.8 | — | 1.0% | Jul 24, 2023 |
37Monitor | CVE-2025-29513No exploit | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Accessnodebb · nodebb · CWE-79 | Medium6.1 | — | 42.8% | Apr 18, 2025 |
37Monitor | CVE-2025-50979No exploit | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories).nodebb · nodebb · CWE-89 | High8.6 | — | 8.5% | Aug 27, 2025 |
34Monitor | CVE-2026-58593No exploit | NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local Usernodebb · nodebb · CWE-290 | High8.7 | — | 0.3% | Jul 1, 2026 |
32Monitor | CVE-2020-15156No exploit | XSS due to lack of CSRF validation for replying/publishingnodebb · blog comments · CWE-352 | High8.1 | — | 0.6% | Aug 26, 2020 |
31Monitor | CVE-2021-43786No exploit | API token verification can be bypassednodebb · nodebb · CWE-287 | High7.5 | — | 2.4% | Nov 29, 2021 |
30Monitor | CVE-2024-57041No exploit | A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' senodebb · nodebb · CWE-79 | Medium4.6 | — | 39.3% | Jan 24, 2025 |
30Monitor | CVE-2022-36076No exploit | Account takeover via SSO plugins in NodeBBnodebb · nodebb · CWE-352 | High7.5 | — | 0.6% | Sep 2, 2022 |
28Monitor | CVE-2021-43788No exploit | Path traversal in translator module of NobeBBnodebb · nodebb · CWE-22 | Medium5.0 | — | 25.8% | Nov 29, 2021 |
25Monitor | CVE-2024-29316No exploit | NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group vnodebb · nodebb | Medium6.3 | — | 0.4% | Mar 28, 2024 |
24Monitor | CVE-2015-9286No exploit | Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.nodebb · nodebb · CWE-79 | Medium6.1 | — | 1.4% | Apr 30, 2019 |
24Monitor | CVE-2021-43787No exploit | XSS via prototype pollutionnodebb · nodebb · CWE-79 | Medium6.1 | — | 1.3% | Nov 29, 2021 |
24Monitor | CVE-2015-3296No exploit | Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vnodebb · nodebb · CWE-79 | Medium6.1 | — | 1.3% | Sep 21, 2017 |
24Monitor | CVE-2025-29512No exploit | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render nodebb · nodebb · CWE-79 | Medium6.1 | — | 0.3% | Apr 18, 2025 |
18Monitor | CVE-2023-2850No exploit | NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin.nodebb · nodebb · CWE-1385 | Medium4.7 | — | 0.3% | Jul 25, 2023 |
17Monitor | CVE-2022-3978No exploit | NodeBB abort cross-site request forgerynodebb · nodebb · CWE-863 | Medium4.3 | — | 0.4% | Nov 13, 2022 |
- CVE-2022-4616454Plan
Account takeover via prototype vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 49%nodebb · nodebbDec 5, 2022
- CVE-2023-4318753Plan
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers
CriticalCVSS 9.8Proof of conceptEPSS 47%nodebb · nodebbSep 27, 2023
- CVE-2023-3059146Plan
NodeBB Pre-Authentication Denial-of-Service
HighCVSS 7.5No exploitEPSS 54%nodebb · nodebbSep 29, 2023
- CVE-2020-1514940Plan
Account takeover in NodeBB
CriticalCVSS 9.9No exploitEPSS 2%nodebb · nodebbAug 19, 2020
- CVE-2022-3604539Monitor
Account takeover via cryptographically weak PRNG in NodeBB Forum
CriticalCVSS 9.8No exploitEPSS 1%nodebb · nodebbAug 31, 2022
- CVE-2023-2604539Monitor
NodeBB vulnerable to path traversal and code execution via prototype vulnerability
CriticalCVSS 9.8No exploitEPSS 1%nodebb · nodebbJul 24, 2023
- CVE-2025-2951337Monitor
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access
MediumCVSS 6.1No exploitEPSS 43%nodebb · nodebbApr 18, 2025
- CVE-2025-5097937Monitor
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories).
HighCVSS 8.6No exploitEPSS 9%nodebb · nodebbAug 27, 2025
- CVE-2026-5859334Monitor
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
HighCVSS 8.7No exploitEPSS 0%nodebb · nodebbJul 1, 2026
- CVE-2020-1515632Monitor
XSS due to lack of CSRF validation for replying/publishing
HighCVSS 8.1No exploitEPSS 1%nodebb · blog commentsAug 26, 2020
- CVE-2021-4378631Monitor
API token verification can be bypassed
HighCVSS 7.5No exploitEPSS 2%nodebb · nodebbNov 29, 2021
- CVE-2024-5704130Monitor
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' se
MediumCVSS 4.6No exploitEPSS 39%nodebb · nodebbJan 24, 2025
- CVE-2022-3607630Monitor
Account takeover via SSO plugins in NodeBB
HighCVSS 7.5No exploitEPSS 1%nodebb · nodebbSep 2, 2022
- CVE-2021-4378828Monitor
Path traversal in translator module of NobeBB
MediumCVSS 5.0No exploitEPSS 26%nodebb · nodebbNov 29, 2021
- CVE-2024-2931625Monitor
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group v
MediumCVSS 6.3No exploitEPSS 0%nodebb · nodebbMar 28, 2024
- CVE-2015-928624Monitor
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
MediumCVSS 6.1No exploitEPSS 1%nodebb · nodebbApr 30, 2019
- CVE-2021-4378724Monitor
XSS via prototype pollution
MediumCVSS 6.1No exploitEPSS 1%nodebb · nodebbNov 29, 2021
- CVE-2015-329624Monitor
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via v
MediumCVSS 6.1No exploitEPSS 1%nodebb · nodebbSep 21, 2017
- CVE-2025-2951224Monitor
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render
MediumCVSS 6.1No exploitEPSS 0%nodebb · nodebbApr 18, 2025
- CVE-2023-285018Monitor
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin.
MediumCVSS 4.7No exploitEPSS 0%nodebb · nodebbJul 25, 2023
- CVE-2022-397817Monitor
NodeBB abort cross-site request forgery
MediumCVSS 4.3No exploitEPSS 0%nodebb · nodebbNov 13, 2022