← Vulnerability feed

Vulnerability record · CVE-2021-43788 · published 29 November 2021

CVE-2021-43788: Nodebb path traversal vulnerability

Nodebb · Nodebb

Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.

5.0 CVSS 3.1 Medium EPSS 26% · top 2.1% CWE-22 · Path traversal
5.0CVSS 3.1 base score, v2 4.0
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43788 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-15149Nodebb improper privilege management vulnerabilityNodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…EPSS 2.4%9.8CVE-2023-43187NodeBB xmlrpc.php XML injection leads to remote code executionNodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code th…EPSS 45%analysed9.8CVE-2023-26045Nodebb path traversal vulnerabilityNodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…EPSS 1.0%9.8CVE-2022-46164NodeBB socket.io prototype handling allows account takeoverNodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over a…EPSS 49%analysed9.8CVE-2022-36045Nodebb vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac…EPSS 1.3%8.7CVE-2026-58593Nodebb authentication bypass by spoofing vulnerabilityNodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-…EPSS 0.29%8.6CVE-2025-50979Nodebb sql injection vulnerabilityNodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…EPSS 8.5%7.5CVE-2023-30591NodeBB Socket.IO event name type confusion denial of serviceNodeBB versions up to and including v2.8.10 crash when processing crafted Socket.IO messages whose event name is an array or object instead of a stri…EPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2021-43788), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.