ROBERT KRUCZEK
← Back to home

CVE-2025-54117

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS v3.1: 9.1 (CRITICAL) Published: August 18, 2025 View on NVD →

Description

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4.

Affected Products

Vendor Product Versions Affected
NamelessMC Nameless < 2.2.4 (affected)

CVSS Score & Vector

Base Score: 9.1 (CRITICAL)
Vector (v3.1):
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H