nodebb
v1.4.0npm· JavaScriptNodeBB Forum
The verdict
Has 9 high-severity advisories. Verify a patched version exists before using. Check the OSV link for the fixed-in version.
Check the OSV link for the fixed-in version.
Live from the npm registry · derived rules, not AI
How it scores
MaintenanceAbandoned
PopularityUnknown
Security9 advisories
LicenseCopyleft
DepsHeavy
Maintenance
Last published 9 years ago.
Popularity
Download count unavailable.
Security
9 known advisories (worst: high severity).
License
GPL-3.0
Dependencies
76 direct dependencies
Security advisories
Live from OSV.dev · cached 24h- HIGHCryptographically weak PRNG in `utils.generateUUID`
- HIGHNodeBB vulnerable to account takeover via prototype vulnerability
- HIGHNodeBB SQL Injection vulnerabilityGHSA-rfh2-8vxq-jqr8 Published 2025-08-27
- HIGHNodeBB account takeover via SSO plugins
- MEDIUMUnintentional leakage of private information via cross-origin websocket session hijacking
- MEDIUMNodeBB vulnerable to Cross-Site Request Forgery
- MEDIUMNodeBB vulnerable to path traversal in translator module
- MEDIUMIncorrect Access Control in NodeBB
- MEDIUMNodeBB Cross-site scripting (XSS) vulnerability
Recent releases
- 1.4.09 years ago
- 0.8.210 years ago
- 0.7.011 years ago
- 0.6.111 years ago
- 0.6.1-dev11 years ago
- 0.4.311 years ago