Vulnerabilities

Summary — last 7 days

New vulnerabilities2,523▼ 417 vs. last week
Critical / high1,297▲ 13 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)60▼ 468 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.1)0.61%—Nodebb Blog Comments8/26/20206/17/2026
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.