We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-30158

NamelessMC Forum iframe width/height abuse causing UI-based Denial of Service



Description

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attributes. This allows an authenticated attacker to perform a UI-based denial of service (DoS) by injecting oversized iframes that block the forum UI and disrupt normal user interactions. This issue has been patched in version 2.2.0.

Reserved 2025-03-17 | Published 2025-04-18 | Updated 2025-04-18 | Assigner GitHub_M


HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Problem types

CWE-400: Uncontrolled Resource Consumption

Product status

< 2.2.0
affected

References

github.com/...meless/security/advisories/GHSA-2prx-rgr7-hq5f

github.com/...ommit/caa42a975338a13fbc1658e8c440108f16135643

github.com/NamelessMC/Nameless/releases/tag/v2.2.0

cve.org (CVE-2025-30158)

nvd.nist.gov (CVE-2025-30158)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-30158

Support options

Helpdesk Chat, Email, Knowledgebase