CVE Tools

Nodebb

5 CVEs tracked since 2020. Since Aug 2020, none of them reached CISA KEV.

Nodebb CVEs per month

Aug 2020 to Nov 2021. Point at a month, or focus the strip and use the arrow keys.
Nodebb CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0820
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-1130

Products

The products that kept showing up in Nodebb's monthly top three, with their CVEs summed over those months.

  1. Nodebb42 months
  2. Blog Comments11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Nodebb.

  1. CVE-2026-73038NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name6.1
  2. CVE-2026-58593NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User7.5
  3. CVE-2021-47746NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write7.5
  4. CVE-2025-50979NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remot...8.6
  5. CVE-2025-29513Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.6.1
  6. CVE-2025-29512Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is ...6.1
  7. CVE-2024-57041A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.4.6
  8. CVE-2024-29316NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.6.3
  9. CVE-2023-30591NodeBB Pre-Authentication Denial-of-Service7.5
  10. CVE-2023-43187A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.9.8
  11. CVE-2023-2850NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extrac...4.7
  12. CVE-2023-26045NodeBB vulnerable to path traversal and code execution via prototype vulnerability10.0
  13. CVE-2022-46164Account takeover via prototype vulnerability9.4
  14. CVE-2022-3978NodeBB abort cross-site request forgery4.3
  15. CVE-2022-36076Account takeover via SSO plugins in NodeBB8.8

The record

Peak rank
#139 in Nov 2021
Busiest month shown
Nov 2021, 3 CVEs
Months with a KEV entry
0 since Aug 2020
Monthly snapshots
2 since 2020
Nodebb's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store