Vulnerabilities > Nodebb > Blog Comments > 0.1.19

DATE CVE VULNERABILITY TITLE RISK
2020-08-26 CVE-2020-15156 Cross-Site Request Forgery (CSRF) vulnerability in Nodebb Blog Comments
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum.
network
nodebb CWE-352
4.3