Barış Soner Uşaklı
11 exploits
Active since Nov 2021
NodeBB Forum Software - Info Disclosure
CVSS 9.0
NodeBB < 2.6.1 - Account Takeover via Prototype Pollution in Socket.IO Message Handling
CVSS 9.4
NodeBB <= 2.8.10 - Unauthenticated Denial of Service via Crafted Socket.IO Messages
CVSS 7.5
NodeBB <= 2.8.10 - Unauthenticated Denial of Service via Crafted Socket.IO Messages
CVSS 7.5
NodeBB 1.15.0-1.18.4 - Unauthenticated Remote Code Execution via Master Token Bypass
CVSS 9.8
NodeBB 1.15.5-1.18.4 - Authenticated DOM-Based Cross-Site Scripting via Prototype Pollution
CVSS 9.0
NodeBB 1.0.4-1.18.4 - Path Traversal via Language File Access
CVSS 5.0
NodeBB Forum Software - Info Disclosure
CVSS 9.0
NodeBB 2.5.0-2.8.6 - Remote Code Execution via User Export Path Traversal
CVSS 10.0
NodeBB < 2.8.13 and 3.0.0-3.1.3 - Cross-Site WebSocket Hijacking via Missing Origin Validation
CVSS 4.7
NodeBB < 3.11.1 - Stored Cross-Site Scripting in Profile About Me Section
CVSS 4.6