Home

Description

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4.

PUBLISHED Reserved 2025-07-21 | Published 2025-08-18 | Updated 2025-08-18 | Assigner GitHub_M




HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

< 2.2.4
affected

References

github.com/...meless/security/advisories/GHSA-f5rm-w4mx-q7rx

github.com/...ommit/56d35cff9ee944c061791ef478cabd2bed0223c4

cve.org (CVE-2025-54421)

nvd.nist.gov (CVE-2025-54421)

Download JSON