CVE-2025-54117

CRITICAL

NamelessMC < 2.2.4 - Authenticated Cross-Site Scripting via Dashboard Text Editor

Title source: llm
STIX 2.1

Description

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4.

Scores

CVSS v3 9.0
EPSS 0.0035
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
namelessmc/nameless < 2.2.4
Published Aug 18, 2025
Tracked Since Feb 18, 2026