NodeBB
Security Risk Profile
42
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 21, 2017 to present
22
Total CVEs
12
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
42/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
7High
5Medium
10Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
8
2
Path Traversal
3
3
CSRF
3
4
SQL Injection
1
5
Weak RNG
1
Most Affected Products
1. nodebb Nodebb26
2. npm/nodebb7
3. NodeBB1
4. nodebb Nodebb Node.js1
5. nodebb Blog Comments Node.js1
Recent Vulnerabilities
See more →CVE-2026-73038
CVSS 6.1medium
NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name
8/13/2026🔧 No Patch
CVE-2026-58593
CVSS 8.7high
NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
7/1/2026🔧 No Patch
CVE-2025-50979
CVSS 8.6high
8/27/2025🔧 No Patch
CVE-2025-29513
CVSS 6.1medium
4/18/2025🔧 No Patch
CVE-2025-29512
CVSS 6.1medium
4/18/2025🔧 No Patch
CVE-2024-57041
CVSS 4.6medium
1/24/2025
CVE-2024-29316
CVSS 6.3EPSS 0%medium
3/28/2024
CVE-2023-30591
CVSS 7.5high
NodeBB Pre-Authentication Denial-of-Service
9/29/2023
CVE-2023-43187
CVSS 9.8critical
9/26/2023🔧 No Patch
CVE-2023-2850
CVSS 4.7medium
7/25/2023
Monitor NodeBB in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.