Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.
References
Link | Resource |
---|---|
http://nodebb.com | Product |
https://www.tonysec.com/posts/cve-2025-29512/ | Third Party Advisory |
Configurations
History
23 Apr 2025, 17:28
Type | Values Removed | Values Added |
---|---|---|
First Time |
Nodebb
Nodebb nodebb |
|
CPE | cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:* | |
Summary |
|
|
References | () http://nodebb.com - Product | |
References | () https://www.tonysec.com/posts/cve-2025-29512/ - Third Party Advisory |
18 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
CWE | CWE-79 |
18 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-18 18:15
Updated : 2025-04-23 17:28
NVD link : CVE-2025-29512
Mitre link : CVE-2025-29512
CVE.ORG link : CVE-2025-29512
JSON object : View
Products Affected
nodebb
- nodebb
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')