CVE-2023-43187: Nodebb

Critical severity, CVSS 9.8. EPSS: 47.4% chance of exploitation in the next 30 days.

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

Affected products

  • Nodebb Nodebb: before 1.18.6 (fixed in 1.18.6)

Published 2023-09-27. Last modified 2026-06-17.