Namelessmc develops a web-based gaming server management platform whose vulnerability profile centers on input-handling and data-exposure weaknesses typical of server-side web applications. The recurring issues include cross-site scripting variants, uncontrolled resource consumption, and exposure of sensitive information, reflecting the challenges of managing user input and session state in a community-facing service. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Namelessmc over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2820HIGH Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. | Aug 15, 2022 | 8.2 | 27 | NO | NO |
CVE-2025-22144CRITICAL NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an att | Jan 13, 2025 | 9.8 | 26 | NO | NO |
CVE-2022-2821HIGH Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | Aug 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-54117MEDIUM NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated | Aug 18, 2025 | 5.4 | 22 | NO | NO |
CVE-2025-29784HIGH NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lack | Apr 18, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-54421MEDIUM NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated | Aug 18, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-54118MEDIUM NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attac | Aug 18, 2025 | 5.3 | 21 | NO | NO |
CVE-2025-31118HIGH NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any s | Apr 18, 2025 | 7.1 | 21 | NO | NO |
CVE-2025-30158HIGH NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/ | Apr 18, 2025 | 7.1 | 21 | NO | NO |
CVE-2025-32389MEDIUM NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected sq | Apr 18, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Namelessmc.
Media articles that mention a CVE ID that affects a product developed by Namelessmc — matched by CVE ID, not by vendor name.