Vulnerability Description
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator deletes the malicious user's account, all their posts (comments) along with the associated topics (by unrelated users) will be marked as deleted. This issue has been patched in version 2.2.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Namelessmc | Nameless | < 2.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/NamelessMC/Nameless/commit/7040924e27f99aa486c619a5b4ca809051Patch
- https://github.com/NamelessMC/Nameless/releases/tag/v2.2.0Release Notes
- https://github.com/NamelessMC/Nameless/security/advisories/GHSA-22mc-7c9m-gv8hExploitVendor Advisory
FAQ
What is CVE-2025-30357?
CVE-2025-30357 is a vulnerability with a CVSS score of 7.3 (HIGH). NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unab...
How severe is CVE-2025-30357?
CVE-2025-30357 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-30357?
Check the references section above for vendor advisories and patch information. Affected products include: Namelessmc Nameless.