Skip to content
Noroxi

nodebb records

21 published records for vendor nodebb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
71.4%
Median publish → KEV
No record has entered KEV

All records

21 records
  • Account takeover via prototype vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 49%

    nodebb · nodebbDec 5, 2022

  • A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    nodebb · nodebbSep 27, 2023

  • NodeBB Pre-Authentication Denial-of-Service

    HighCVSS 7.5No exploitEPSS 54%

    nodebb · nodebbSep 29, 2023

  • Account takeover in NodeBB

    CriticalCVSS 9.9No exploitEPSS 2%

    nodebb · nodebbAug 19, 2020

  • Account takeover via cryptographically weak PRNG in NodeBB Forum

    CriticalCVSS 9.8No exploitEPSS 1%

    nodebb · nodebbAug 31, 2022

  • NodeBB vulnerable to path traversal and code execution via prototype vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    nodebb · nodebbJul 24, 2023

  • Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access

    MediumCVSS 6.1No exploitEPSS 43%

    nodebb · nodebbApr 18, 2025

  • NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories).

    HighCVSS 8.6No exploitEPSS 9%

    nodebb · nodebbAug 27, 2025

  • NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User

    HighCVSS 8.7No exploitEPSS 0%

    nodebb · nodebbJul 1, 2026

  • XSS due to lack of CSRF validation for replying/publishing

    HighCVSS 8.1No exploitEPSS 1%

    nodebb · blog commentsAug 26, 2020

  • API token verification can be bypassed

    HighCVSS 7.5No exploitEPSS 2%

    nodebb · nodebbNov 29, 2021

  • A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' se

    MediumCVSS 4.6No exploitEPSS 39%

    nodebb · nodebbJan 24, 2025

  • Account takeover via SSO plugins in NodeBB

    HighCVSS 7.5No exploitEPSS 1%

    nodebb · nodebbSep 2, 2022

  • Path traversal in translator module of NobeBB

    MediumCVSS 5.0No exploitEPSS 26%

    nodebb · nodebbNov 29, 2021

  • NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group v

    MediumCVSS 6.3No exploitEPSS 0%

    nodebb · nodebbMar 28, 2024

  • CVE-2015-9286
    24Monitor

    Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    nodebb · nodebbApr 30, 2019

  • XSS via prototype pollution

    MediumCVSS 6.1No exploitEPSS 1%

    nodebb · nodebbNov 29, 2021

  • CVE-2015-3296
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via v

    MediumCVSS 6.1No exploitEPSS 1%

    nodebb · nodebbSep 21, 2017

  • Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render

    MediumCVSS 6.1No exploitEPSS 0%

    nodebb · nodebbApr 18, 2025

  • CVE-2023-2850
    18Monitor

    NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin.

    MediumCVSS 4.7No exploitEPSS 0%

    nodebb · nodebbJul 25, 2023

  • CVE-2022-3978
    17Monitor

    NodeBB abort cross-site request forgery

    MediumCVSS 4.3No exploitEPSS 0%

    nodebb · nodebbNov 13, 2022