Количество 2
Количество 2
CVE-2025-50979
6 месяцев назад
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.
CVSS3: 8.6
EPSS: Низкий
GHSA-rfh2-8vxq-jqr8
6 месяцев назад
NodeBB SQL Injection vulnerability
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-50979 NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads. | CVSS3: 8.6 | 0% Низкий | 6 месяцев назад | |
GHSA-rfh2-8vxq-jqr8 NodeBB SQL Injection vulnerability | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу
20