Browse all 10 CVE security advisories affecting NodeBB. AI-powered Chinese analysis, POCs, and references for each vulnerability.
NodeBB serves as a Node.js-based forum platform enabling real-time discussion communities. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control flaws. While no major public security incidents have been widely documented, the platform maintains 10 CVEs on record, highlighting ongoing security considerations. Its real-time architecture introduces unique attack surfaces, particularly around WebSocket implementations and plugin ecosystems. Regular security updates and careful configuration are essential for maintaining secure deployments, as evidenced by its vulnerability history.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-2850 | NodeBB 访问控制错误漏洞 — NodeBBCWE-1385 | 4.7 | Medium | 2023-07-25 |
| CVE-2023-26045 | NodeBB vulnerable to path traversal and code execution via prototype vulnerability — NodeBBCWE-22 | 10.0 | Critical | 2023-07-24 |
| CVE-2022-46164 | Account takeover via prototype vulnerability — NodeBBCWE-665 | 9.4 | Critical | 2022-12-05 |
| CVE-2022-36076 | Account takeover via SSO plugins in NodeBB — NodeBBCWE-352 | 8.8 | High | 2022-09-02 |
| CVE-2022-36045 | Account takeover via cryptographically weak PRNG in NodeBB Forum — NodeBBCWE-330 | 9.0 | Critical | 2022-08-31 |
| CVE-2021-43788 | Path traversal in translator module of NobeBB — NodeBBCWE-22 | 5.0 | Medium | 2021-11-29 |
| CVE-2021-43786 | API token verification can be bypassed — NodeBBCWE-287 | 9.8 | Critical | 2021-11-29 |
| CVE-2021-43787 | XSS via prototype pollution — NodeBBCWE-79 | 9.0 | Critical | 2021-11-29 |
| CVE-2020-15149 | Account takeover in NodeBB — NodeBBCWE-269 | 9.9 | Critical | 2020-08-19 |
This page lists every published CVE security advisory associated with NodeBB. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.