← Back

CVE-2025-29512

nvd nist
Published: Apr 18, 2025Modified: Apr 23, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.

Affected (1)

Products: Nodebb: Nodebb
1 product
Nodebb
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.0.4

References (2)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.