Products: 2
Vulnerabilities: 23
Known Exploited: 0
7
Critical Level Threats
5
High Level Threats
11
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-73038
NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name
Last Modified: Aug 14, 2026
Published: Aug 13, 2026
CVE-2026-58593
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
Last Modified: Jul 07, 2026
Published: Jul 01, 2026
CVE-2021-47746
NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write
Last Modified: Apr 15, 2026
Published: Jan 21, 2026
CVE-2025-50979
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.
Last Modified: Sep 09, 2025
Published: Aug 27, 2025
CVE-2025-29512
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.
Last Modified: Apr 23, 2025
Published: Apr 18, 2025
Items Per Page
