← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 13, 2026 · 18:41via CVEFeed

CVE-2026-73038 - NodeBB 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name

Brief

CVE ID : CVE-2026-73038

Published : Aug. 13, 2026, 6:41 p. m.

  • 23 minutes ago

Description : NodeBB before 4.

  • 0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag. icon. url and tag. name attributes. Attackers can deliver malicious ActivityPub Create/Note objects with crafted emoji tags to inject arbitrary HTML and JavaScript into stored post content, executing code in all viewers' browsers.

Severity: 6.1

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed