ZeroHour

CVE-2025-54117

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p32
Published
()
Modified
Description

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4.

Vendors
namelessmc
Products
nameless
Weakness
CWE-79, CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.