Medium severity6.1NVD Advisory· Published Apr 18, 2025· Updated Jul 5, 2026
CVE-2025-29512
CVE-2025-29512
Description
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- www.tonysec.com/posts/cve-2025-29512/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.