Nodebb: community verdicts
2 notable / known-exploited Nodebb CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Nodebb CVE, see NVD ↗.
- CVE-2024-57041MED 4.6EPSS 39%
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
- CVE-2025-29513MED 6.1EPSS 25%
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.