
NodeBB Patches Eight High-Severity Flaws Enabling XSS, Admin Bypass, and Data Theft
A newly disclosed eight high-severity vulnerabilities in NodeBB, a popular Node.js-based forum platform, all discovered during a six-hour AI-driven whitebox penetration test. The flaws affected default NodeBB instances prior to version 4.14.0 and included cross-site scripting (XSS), authentication bypasses, and unauthorized data exposure. NodeBB’s maintainers responded quickly, rolling out fixes in early July 2026. NodeBB […]
The post NodeBB Patches Eight High-Severity Flaws Enabling XSS, Admin Bypass, and Data Theft appeared first on Cyber Security News.