Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53506 | NodeBB Cross-site scripting (XSS) vulnerability |
Github GHSA |
GHSA-vqr3-vrrg-f3jh | NodeBB Cross-site scripting (XSS) vulnerability |
Fri, 27 Jun 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodebb
Nodebb nodebb |
|
| CPEs | cpe:2.3:a:nodebb:nodebb:3.11.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Nodebb
Nodebb nodebb |
Fri, 07 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Feb 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 24 Jan 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-06T21:27:03.283Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57041
Updated: 2025-01-24T21:15:58.934Z
Status : Analyzed
Published: 2025-01-24T20:15:33.353
Modified: 2025-06-27T19:33:21.410
Link: CVE-2024-57041
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA