Medium severity6.8NVD Advisory· Published Aug 26, 2020· Updated Jun 17, 2026
CVE-2020-15156
CVE-2020-15156
Description
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nodebb-plugin-blog-commentsnpm | < 0.7.0 | 0.7.0 |
Affected products
3- Range: < 0.7.0
Patches
Vulnerability mechanics
References
5- github.com/psychobunny/nodebb-plugin-blog-comments/commit/cf43beedb05131937ef46f365ab0a0c6fa6ac618nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-43m5-c88r-cjvvghsaADVISORY
- github.com/psychobunny/nodebb-plugin-blog-comments/security/advisories/GHSA-43m5-c88r-cjvvnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15156ghsaADVISORY
- www.npmjs.com/package/nodebb-plugin-blog-commentsnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.