Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25915 | NodeBB SQL Injection vulnerability |
Github GHSA |
GHSA-rfh2-8vxq-jqr8 | NodeBB SQL Injection vulnerability |
Tue, 09 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nodebb:nodebb:4.3.0:-:*:*:*:*:*:* |
Thu, 28 Aug 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodebb
Nodebb nodebb |
|
| Vendors & Products |
Nodebb
Nodebb nodebb |
Wed, 27 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 27 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-27T18:24:03.996Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50979
Updated: 2025-08-27T18:22:22.520Z
Status : Analyzed
Published: 2025-08-27T18:15:45.820
Modified: 2025-09-09T18:45:06.613
Link: CVE-2025-50979
No data.
OpenCVE Enrichment
Updated: 2025-08-28T07:40:57Z
EUVD
Github GHSA