nodebb
GPL-3.0NodeBB Forum
20
Security score
9 known advisories in v1.4.0
OpenSSF Scorecard 5.4/10
Weekly downloads
—
Unpacked size
—
Dependencies
76
Last publish
9 years ago
Security advisories
- Unintentional leakage of private information via cross-origin websocket session hijackingmoderate
GHSA-4qcv-qf38-5j3j · fixed in 3.1.3, 2.8.13
- NodeBB vulnerable to Cross-Site Request Forgerymoderate
GHSA-5gwx-wf9g-r5mx · fixed in 2.5.8
- Cryptographically weak PRNG in `utils.generateUUID`critical
GHSA-p4cc-w597-6cpm · fixed in 1.19.8, 2.0.1
- NodeBB vulnerable to path traversal in translator modulemoderate
GHSA-pfj7-2qfw-vwgm · fixed in 1.18.5
- Incorrect Access Control in NodeBBmoderate
GHSA-qc99-r4wh-c8h6 · fixed in 3.6.7
- NodeBB vulnerable to account takeover via prototype vulnerabilitycritical
GHSA-rf3g-v8p5-p675 · fixed in 2.6.1
- NodeBB SQL Injection vulnerabilityhigh
GHSA-rfh2-8vxq-jqr8
- NodeBB Cross-site scripting (XSS) vulnerabilitymoderate
GHSA-vqr3-vrrg-f3jh · fixed in 3.11.1
- NodeBB account takeover via SSO pluginshigh
GHSA-xmgg-fx9p-prq6 · fixed in 1.17.2
OpenSSF ScorecardJul 20, 2026
- Code-Review0
- Dangerous-Workflow10
- Token-Permissions0
- Maintained10
- Security-Policy10
- CII-Best-Practices0
- License10
- Binary-Artifacts10
- Fuzzing0
- SAST0
- Packaging10
- Pinned-Dependencies0