NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*:* |
Mon, 18 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Namelessmc
Namelessmc nameless |
|
Vendors & Products |
Namelessmc
Namelessmc nameless |
Mon, 18 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 18 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4. | |
Title | NamelessMC allows Stored Cross Site Scripting (XSS) in SEO component | |
Weaknesses | CWE-79 CWE-80 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-18T16:01:30.994Z
Updated: 2025-08-18T17:36:09.856Z
Reserved: 2025-07-21T23:18:10.281Z
Link: CVE-2025-54421

Updated: 2025-08-18T17:36:03.873Z

Status : Analyzed
Published: 2025-08-18T16:15:29.540
Modified: 2025-08-20T21:23:41.550
Link: CVE-2025-54421

No data.