CVE-2025-54117
- EPSS 0.04%
- Veröffentlicht 18.08.2025 16:15:29
- Zuletzt bearbeitet 20.08.2025 21:23:49
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard te...
CVE-2025-54118
- EPSS 0.08%
- Veröffentlicht 18.08.2025 16:15:29
- Zuletzt bearbeitet 20.08.2025 21:23:34
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source ...
CVE-2025-54421
- EPSS 0.03%
- Veröffentlicht 18.08.2025 16:15:29
- Zuletzt bearbeitet 20.08.2025 21:23:41
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keyw...
CVE-2025-32389
- EPSS 0.21%
- Veröffentlicht 18.04.2025 15:56:39
- Zuletzt bearbeitet 13.05.2025 15:23:15
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax...
CVE-2025-31120
- EPSS 0.2%
- Veröffentlicht 18.04.2025 15:52:57
- Zuletzt bearbeitet 13.05.2025 15:24:49
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The applic...
CVE-2025-31118
- EPSS 0.39%
- Veröffentlicht 18.04.2025 15:52:36
- Zuletzt bearbeitet 13.05.2025 15:27:06
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuou...
CVE-2025-30357
- EPSS 0.27%
- Veröffentlicht 18.04.2025 15:51:21
- Zuletzt bearbeitet 13.05.2025 15:40:18
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delet...
CVE-2025-30158
- EPSS 0.39%
- Veröffentlicht 18.04.2025 15:50:49
- Zuletzt bearbeitet 13.05.2025 15:40:58
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height att...
CVE-2025-29784
- EPSS 0.41%
- Veröffentlicht 18.04.2025 15:50:17
- Zuletzt bearbeitet 13.05.2025 15:41:25
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long sea...
CVE-2025-22142
- EPSS 0.72%
- Veröffentlicht 13.01.2025 20:15:29
- Zuletzt bearbeitet 13.05.2025 15:19:03
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated onc...