Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.38% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private or blocking profile… | |
| Aplazada | Media (6.9) | 0.44% | — | Namelessmc Nameless MCAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reaction details. This… | |
| Aplazada | Media (5.3) | 0.38% | — | NamelessmcAI | 2/6/2026 | 22/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to… | |
| Aplazada | Media (5.3) | 0.38% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the forum but may only… | |
| Aplazada | Media (5.4) | 0.13% | — | NamelessmcAI | 2/6/2026 | 22/7/2026 | NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging the authorization code. This allows an attacker to capture a valid OAuth callback URL for their own account and cause a victim's browser to… | |
| Aplazada | Alta (7.1) | 0.38% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled `post` ID and returns its content. The backend helper in `modules/Forum/classes/Forum.php` does not enforce forum or… | |
| Aplazada | Media (4.3) | 0.30% | — | NamelessmcAI | 2/6/2026 | 21/7/2026 | NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response without proper… | |
| Analizada | Media (5.4) | 0.39% | — | Namelessmc Nameless | 18/8/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4. | |
| Analizada | Media (5.3) | 0.43% | — | Namelessmc Nameless | 18/8/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4. | |
| Analizada | Media (5.4) | 0.39% | — | Namelessmc Nameless | 18/8/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4. | |
| Analizada | Alta (8.6) | 0.50% | — | Namelessmc Nameless | 18/4/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refers to the structure `?param[0]=a¶m[1]=b¶m[2]=c` utilized… | |
| Analizada | Media (5.3) | 0.47% | — | Namelessmc Nameless | 18/4/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The application relies on a client-side cookie (nl-topic-[tid]) (or session… | |
| Analizada | Alta (7.1) | 0.55% | — | Namelessmc Nameless | 18/4/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously post replies without any time restriction, resulting in an… | |
| Analizada | Media (6.8) | 0.46% | — | Namelessmc Nameless | 18/4/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator deletes the malicious… | |
| Analizada | Alta (7.1) | 0.55% | — | Namelessmc Nameless | 18/4/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attributes. This allows an authenticated attacker to perform a UI-based… | |
| Analizada | Alta (7.5) | 0.65% | — | Namelessmc Nameless | 18/4/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search queries. This oversight can lead to performance degradation and… | |
| Analizada | Crítica (9) | 0.76% | — | Namelessmc Nameless | 13/1/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually… | |
| Analizada | Media (6.3) | 0.28% | — | Namelessmc Nameless | 13/1/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated once a staffer visits the user's profile on staff panel. As a result an… | |
| Modificada | Alta (7.5) | 1.3% | — | Namelessmc Nameless | 15/8/2022 | 17/6/2026 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | |
| Modificada | Alta (8.2) | 0.70% | — | Namelessmc Nameless | 15/8/2022 | 17/6/2026 | Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. |