We have released NodeBB versions v2.8.18, v3.12.5, and v4.3.2 to address a security issue involving a potential XSS vector and a SQL injection vulnerability. We strongly recommend all users update to the latest patch version for their respective branches:
v4.3.2 Release Notes
v3.12.5 Release Notes
v2.8.18 Release Notes
If you discover a vulnerability, please report it responsibly via our bug bounty program.
As mentioned before, we are going to support 2.x to to August 2025.