← Vulnerability feed

Vulnerability record · CVE-2023-43187 · published 27 September 2023

CVE-2023-43187: NodeBB xmlrpc.php XML injection leads to remote code execution

Nodebb · Nodebb

NodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code through crafted XML-RPC requests. It matters because the endpoint is network-reachable and the flaw yields full code execution on the forum host.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.2% CWE-91 · XML injection
9.8CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score and high EPSS probability, with a public exploit reference available.

What it is

NodeBB forum software before v1.18.6 contains an XML injection flaw (CWE-91) in the xmlrpc.php endpoint that lets attackers execute arbitrary code through crafted XML-RPC requests. It matters because the endpoint is network-reachable and the flaw yields full code execution on the forum host.

Impact

An unauthenticated attacker can run arbitrary code on the server, giving full control of the NodeBB instance and any data or credentials it can reach.

Attack surface

Reached over the network via the xmlrpc.php endpoint; the CVSS vector shows no privileges and no user interaction required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.454 (98.7th percentile) and a public exploit reference exists, so exploitation is plausible and should be treated as imminent.

What to do

  • Upgrade NodeBB to v1.18.6 or later immediately.
  • If patching is delayed, block or restrict access to xmlrpc.php at the reverse proxy or WAF.
  • Disable XML-RPC functionality if the forum does not require it.
  • Monitor and rate-limit XML-RPC request volume to the endpoint.
  • Verify no unauthorized code or web shells were placed on the host after exposure.

Detection

  • Alert on POST requests to /xmlrpc.php, especially with unusual XML bodies or oversized payloads.
  • Inspect web and application logs for XML-RPC calls followed by unexpected process execution or file writes.
  • Hunt for new or modified files under the NodeBB web root and for outbound connections from the forum host.
  • Correlate xmlrpc.php access with child processes spawned by the Node.js service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-43187 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2020-15149Nodebb improper privilege management vulnerabilityNodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…EPSS 2.4%9.8CVE-2023-26045Nodebb path traversal vulnerabilityNodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment s…EPSS 1.0%9.8CVE-2022-46164NodeBB socket.io prototype handling allows account takeoverNodeBB uses a plain object with a prototype in socket.io message handling, so a specially crafted payload can impersonate other users and take over a…EPSS 49%analysed9.8CVE-2022-36045Nodebb vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interac…EPSS 1.3%8.7CVE-2026-58593Nodebb authentication bypass by spoofing vulnerabilityNodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-…EPSS 0.29%8.6CVE-2025-50979Nodebb sql injection vulnerabilityNodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not pro…EPSS 8.5%7.5CVE-2023-30591NodeBB Socket.IO event name type confusion denial of serviceNodeBB versions up to and including v2.8.10 crash when processing crafted Socket.IO messages whose event name is an array or object instead of a stri…EPSS 54%analysed7.5CVE-2022-36076Nodebb cross-site request forgery vulnerabilityNodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional …EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2023-43187), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.