📦 Nameless

by Namelessmc

🔍 What is Nameless?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54117

CRITICAL CVSS 9.0 Aug 18, 2025

A stored cross-site scripting (XSS) vulnerability in NamelessMC's dashboard text editor allows authenticated attackers to inject malicious scripts that execute in victims' browsers. This affects all N...

CVE-2025-22144

CRITICAL CVSS 9.8 Jan 13, 2025

This vulnerability in NamelessMC allows attackers with admincp.core.emails or admincp.users.edit permissions to reset user passwords and take over accounts. When accounts are manually validated by pri...

CVE-2025-54421

HIGH CVSS 7.2 Aug 18, 2025

This cross-site scripting (XSS) vulnerability in NamelessMC allows authenticated attackers to inject malicious scripts into web pages via the default_keywords parameter. Attackers can steal session co...

CVE-2025-29784

HIGH CVSS 7.5 Apr 18, 2025

NamelessMC versions 2.1.4 and earlier have a vulnerability in forum search functionality where the 's' parameter in GET requests lacks length validation. Attackers can submit excessively long search q...

CVE-2025-30357

HIGH CVSS 7.3 Apr 18, 2025

In NamelessMC versions 2.1.4 and earlier, when an administrator deletes a spammer's account, all posts by that user are deleted along with entire discussion topics created by other users. This affects...

CVE-2025-31120

MEDIUM CVSS 5.3 Apr 18, 2025

This vulnerability allows unauthenticated attackers to artificially inflate forum view counts in NamelessMC. The insecure mechanism relies on client-side cookies to track views, so requests without th...

CVE-2025-22142

MEDIUM CVSS 5.4 Jan 13, 2025

This is a stored cross-site scripting (XSS) vulnerability in NamelessMC where administrators can add custom user profile fields that accept JavaScript input. When staff members view affected user prof...