Products: 2
    Vulnerabilities: 23
    Known Exploited: 0
    7
    Critical Level Threats
    5
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-73038

    NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-58593

    NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User

    Last Modified: Jul 07, 2026
    Published: Jul 01, 2026

    CVE-2021-47746

    NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write

    Last Modified: Apr 15, 2026
    Published: Jan 21, 2026

    CVE-2025-50979

    NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.

    Last Modified: Sep 09, 2025
    Published: Aug 27, 2025

    CVE-2025-29512

    Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.

    Last Modified: Apr 23, 2025
    Published: Apr 18, 2025
    Items Per Page