CVE-2025-29513

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/04/2025
Last modified:
23/04/2025

Description

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodebb:nodebb:*:*:*:*:*:*:*:* 4.0.4 (including)


References to Advisories, Solutions, and Tools