psychobunny

1 exploit Active since Aug 2020
CVE-2020-15156 WRITEUP MEDIUM WRITEUP
nodebb-plugin-blog-comments <0.7.0 - XSS
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.
CVSS 6.8