CVE-2025-29512: XSS
Published Apr 18, 2025
·Updated
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.
Affected Software
2 affected components
nodebb Nodebb<4.0.4
nodebb Nodebb<=4.0.4
Event History
Apr 18, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29512?
CVE-2025-29512 has been classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-29512?
To fix CVE-2025-29512, upgrade NodeBB to version 4.0.5 or later.
3
Who is affected by CVE-2025-29512?
CVE-2025-29512 affects NodeBB versions prior to 4.0.4.
4
What can remote attackers do with CVE-2025-29512?
Remote attackers can exploit CVE-2025-29512 to store arbitrary code, affecting site security and functionality.
5
Is there a risk of data loss due to CVE-2025-29512?
Yes, if exploited, CVE-2025-29512 can render the blacklist IP functionality unusable, potentially leading to data loss until the affected content is removed.