nodebb kayıtları
nodebb üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-330 Use of Insufficiently Random Values1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2022-46164Kavram kanıtı | Account takeover via prototype vulnerabilitynodebb · nodebb · CWE-665 | Kritik9,8 | — | %49,0 | 5 Ara 2022 |
53Planlayın | CVE-2023-43187Kavram kanıtı | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackersnodebb · nodebb · CWE-91 | Kritik9,8 | — | %46,9 | 27 Eyl 2023 |
46Planlayın | CVE-2023-30591İstismar yok | NodeBB Pre-Authentication Denial-of-Servicenodebb · nodebb · CWE-241 | Yüksek7,5 | — | %53,8 | 29 Eyl 2023 |
40Planlayın | CVE-2020-15149İstismar yok | Account takeover in NodeBBnodebb · nodebb · CWE-269 | Kritik9,9 | — | %2,4 | 19 Ağu 2020 |
39İzleyin | CVE-2022-36045İstismar yok | Account takeover via cryptographically weak PRNG in NodeBB Forumnodebb · nodebb · CWE-330 | Kritik9,8 | — | %1,3 | 31 Ağu 2022 |
39İzleyin | CVE-2023-26045İstismar yok | NodeBB vulnerable to path traversal and code execution via prototype vulnerabilitynodebb · nodebb · CWE-22 | Kritik9,8 | — | %1,0 | 24 Tem 2023 |
37İzleyin | CVE-2025-29513İstismar yok | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Accessnodebb · nodebb · CWE-79 | Orta6,1 | — | %42,8 | 18 Nis 2025 |
37İzleyin | CVE-2025-50979İstismar yok | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories).nodebb · nodebb · CWE-89 | Yüksek8,6 | — | %8,5 | 27 Ağu 2025 |
34İzleyin | CVE-2026-58593İstismar yok | NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local Usernodebb · nodebb · CWE-290 | Yüksek8,7 | — | %0,3 | 1 Tem 2026 |
32İzleyin | CVE-2020-15156İstismar yok | XSS due to lack of CSRF validation for replying/publishingnodebb · blog comments · CWE-352 | Yüksek8,1 | — | %0,6 | 26 Ağu 2020 |
31İzleyin | CVE-2021-43786İstismar yok | API token verification can be bypassednodebb · nodebb · CWE-287 | Yüksek7,5 | — | %2,4 | 29 Kas 2021 |
30İzleyin | CVE-2024-57041İstismar yok | A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' senodebb · nodebb · CWE-79 | Orta4,6 | — | %39,3 | 24 Oca 2025 |
30İzleyin | CVE-2022-36076İstismar yok | Account takeover via SSO plugins in NodeBBnodebb · nodebb · CWE-352 | Yüksek7,5 | — | %0,6 | 2 Eyl 2022 |
28İzleyin | CVE-2021-43788İstismar yok | Path traversal in translator module of NobeBBnodebb · nodebb · CWE-22 | Orta5,0 | — | %25,8 | 29 Kas 2021 |
25İzleyin | CVE-2024-29316İstismar yok | NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group vnodebb · nodebb | Orta6,3 | — | %0,4 | 28 Mar 2024 |
24İzleyin | CVE-2015-9286İstismar yok | Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.nodebb · nodebb · CWE-79 | Orta6,1 | — | %1,4 | 30 Nis 2019 |
24İzleyin | CVE-2021-43787İstismar yok | XSS via prototype pollutionnodebb · nodebb · CWE-79 | Orta6,1 | — | %1,3 | 29 Kas 2021 |
24İzleyin | CVE-2015-3296İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vnodebb · nodebb · CWE-79 | Orta6,1 | — | %1,3 | 21 Eyl 2017 |
24İzleyin | CVE-2025-29512İstismar yok | Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render nodebb · nodebb · CWE-79 | Orta6,1 | — | %0,3 | 18 Nis 2025 |
18İzleyin | CVE-2023-2850İstismar yok | NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin.nodebb · nodebb · CWE-1385 | Orta4,7 | — | %0,3 | 25 Tem 2023 |
17İzleyin | CVE-2022-3978İstismar yok | NodeBB abort cross-site request forgerynodebb · nodebb · CWE-863 | Orta4,3 | — | %0,4 | 13 Kas 2022 |
- CVE-2022-4616454Planlayın
Account takeover via prototype vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %49nodebb · nodebb5 Ara 2022
- CVE-2023-4318753Planlayın
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers
KritikCVSS 9,8Kavram kanıtıEPSS %47nodebb · nodebb27 Eyl 2023
- CVE-2023-3059146Planlayın
NodeBB Pre-Authentication Denial-of-Service
YüksekCVSS 7,5İstismar yokEPSS %54nodebb · nodebb29 Eyl 2023
- CVE-2020-1514940Planlayın
Account takeover in NodeBB
KritikCVSS 9,9İstismar yokEPSS %2nodebb · nodebb19 Ağu 2020
- CVE-2022-3604539İzleyin
Account takeover via cryptographically weak PRNG in NodeBB Forum
KritikCVSS 9,8İstismar yokEPSS %1nodebb · nodebb31 Ağu 2022
- CVE-2023-2604539İzleyin
NodeBB vulnerable to path traversal and code execution via prototype vulnerability
KritikCVSS 9,8İstismar yokEPSS %1nodebb · nodebb24 Tem 2023
- CVE-2025-2951337İzleyin
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access
OrtaCVSS 6,1İstismar yokEPSS %43nodebb · nodebb18 Nis 2025
- CVE-2025-5097937İzleyin
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories).
YüksekCVSS 8,6İstismar yokEPSS %9nodebb · nodebb27 Ağu 2025
- CVE-2026-5859334İzleyin
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
YüksekCVSS 8,7İstismar yokEPSS %0nodebb · nodebb1 Tem 2026
- CVE-2020-1515632İzleyin
XSS due to lack of CSRF validation for replying/publishing
YüksekCVSS 8,1İstismar yokEPSS %1nodebb · blog comments26 Ağu 2020
- CVE-2021-4378631İzleyin
API token verification can be bypassed
YüksekCVSS 7,5İstismar yokEPSS %2nodebb · nodebb29 Kas 2021
- CVE-2024-5704130İzleyin
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' se
OrtaCVSS 4,6İstismar yokEPSS %39nodebb · nodebb24 Oca 2025
- CVE-2022-3607630İzleyin
Account takeover via SSO plugins in NodeBB
YüksekCVSS 7,5İstismar yokEPSS %1nodebb · nodebb2 Eyl 2022
- CVE-2021-4378828İzleyin
Path traversal in translator module of NobeBB
OrtaCVSS 5,0İstismar yokEPSS %26nodebb · nodebb29 Kas 2021
- CVE-2024-2931625İzleyin
NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group v
OrtaCVSS 6,3İstismar yokEPSS %0nodebb · nodebb28 Mar 2024
- CVE-2015-928624İzleyin
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
OrtaCVSS 6,1İstismar yokEPSS %1nodebb · nodebb30 Nis 2019
- CVE-2021-4378724İzleyin
XSS via prototype pollution
OrtaCVSS 6,1İstismar yokEPSS %1nodebb · nodebb29 Kas 2021
- CVE-2015-329624İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via v
OrtaCVSS 6,1İstismar yokEPSS %1nodebb · nodebb21 Eyl 2017
- CVE-2025-2951224İzleyin
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render
OrtaCVSS 6,1İstismar yokEPSS %0nodebb · nodebb18 Nis 2025
- CVE-2023-285018İzleyin
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin.
OrtaCVSS 4,7İstismar yokEPSS %0nodebb · nodebb25 Tem 2023
- CVE-2022-397817İzleyin
NodeBB abort cross-site request forgery
OrtaCVSS 4,3İstismar yokEPSS %0nodebb · nodebb13 Kas 2022