CVE-2015-3296: Nodebb
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.
Affected products
- Nodebb Nodebb: up to and including 0.6.1
Published 2017-09-21. Last modified 2026-06-17.