CVE-2025-54118

MEDIUM

NamelessMC < 2.2.4 - Unauthenticated Sensitive Information Exposure via List Parameter

Title source: llm
STIX 2.1

Description

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4.

Scores

CVSS v3 5.3
EPSS 0.0040
EPSS Percentile 31.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
namelessmc/nameless < 2.2.4
Published Aug 18, 2025
Tracked Since Feb 18, 2026