CVE-2025-29513

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 18, 2025
Updated: Apr 23, 2025
CWE ID 79

Summary

CVE-2025-29513 is a Cross-Site Scripting (XSS) vulnerability affecting NodeBB versions 4.0.4 and older. This issue allows remote attackers to inject malicious code into the admin API Access token generator. Successful exploitation could result in unauthorized access to administrative functions or data within the NodeBB platform. Users are strongly encouraged to update their installations to the latest version to mitigate this risk. The XSS vulnerability could potentially be used to steal sensitive information or carry out further attacks on unsuspecting users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share