CVE-2025-29512: Nodebb

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.

Affected products

  • Nodebb Nodebb: up to and including 4.0.4

Published 2025-04-18. Last modified 2026-07-05.