Vulnerability Description
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Namelessmc | Nameless | < 2.2.4 |
Related Weaknesses (CWE)
References
- https://github.com/NamelessMC/Nameless/commit/56d35cff9ee944c061791ef478cabd2bedPatch
- https://github.com/NamelessMC/Nameless/security/advisories/GHSA-f5rm-w4mx-q7rxExploitVendor Advisory
FAQ
What is CVE-2025-54421?
CVE-2025-54421 is a vulnerability with a CVSS score of 7.2 (HIGH). NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject...
How severe is CVE-2025-54421?
CVE-2025-54421 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54421?
Check the references section above for vendor advisories and patch information. Affected products include: Namelessmc Nameless.