CVE-2024-57041: Nodebb

Medium severity, CVSS 4.6. EPSS: 39.3% chance of exploitation in the next 30 days.

A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.

Affected products

  • Nodebb Nodebb: version 3.11.0 only

Published 2025-01-24. Last modified 2026-07-05.