Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Nameless — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Nameless, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities in Nameless, an unspecified software vendor, categorized under various weakness types and tagged for easy retrieval. It aggregates vulnerability reports from multiple sources, covering data from 2015 through 2024 to provide a comprehensive historical view of security issues affecting the product. Users can utilize this resource to track vendor advisories and patch releases, gain a deeper understanding of specific weakness classes prevalent in the ecosystem, and look up the complete vulnerability history for Nameless. This information is intended for security professionals, developers, and system administrators who need to assess risk, prioritize remediation efforts, and maintain the integrity of their systems. The data is compiled from public advisories, vendor notifications, and community reports, ensuring a broad perspective on the threat landscape. While the vendor name is listed as Nameless, the actual organization may vary, and users should verify the specific entity associated with the product during their analysis. By presenting these details in a structured format, the page facilitates efficient research and informed decision-making regarding software security posture. All entries are linked to relevant identifiers and dates for traceability. This aggregation serves as a neutral reference point, avoiding endorsement or criticism of any specific vendor or product version. The goal is to enhance transparency and awareness regarding known weaknesses.

Vendor: NamelessMC

CVE ID Title CVSS Severity Published
CVE-2026-40571 NamelessMC: Reactions on private or blocking profile posts can be modified without proper authorization CWE-862 - - 2026-06-02
CVE-2026-35447 NamelessMC: Private or blocking profile pages can be bypassed with direct POST requests, and reply handling allows cross-profile writes CWE-201 - - 2026-06-02
CVE-2026-40314 NamelessMC: Reactions on private or blocking profile posts can be read and modified without proper authorization CWE-862 - - 2026-06-02
CVE-2026-35443 NamelessMC: Forum reactions bypass the "view own topics only" restriction CWE-862 - - 2026-06-02
CVE-2026-34460 NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping CWE-302 5.4 Medium 2026-06-02
CVE-2026-33398 Authenticated users can read hidden forum posts through `/forum/get_quotes` CWE-285 - - 2026-06-02
CVE-2026-32250 NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index.php?route=/queries/user/ CWE-79 4.3 Medium 2026-06-02
CVE-2025-54117 NamelessMC allows Stored Cross-Site Scripting (XSS) in dashboard text editor CWE-80 9.1 Critical 2025-08-18
CVE-2025-54421 NamelessMC allows Stored Cross Site Scripting (XSS) in SEO component CWE-79 7.2 High 2025-08-18
CVE-2025-54118 NamelessMC allows sensitive information disclosure in member list component CWE-200 5.3 Medium 2025-08-18
CVE-2025-32389 NamelessMC Vulnerable to SQL Injections in /user/messaging and /panel/users/reports Pages CWE-89 9.8 - 2025-04-18
CVE-2025-31120 NamelessMC Vulnerable to Cookie-Based View Count Manipulation CWE-565 5.3 Medium 2025-04-18
CVE-2025-31118 NamelessMC Has Forum Reply Submission Time Limit Bypass CWE-400 7.1 High 2025-04-18
CVE-2025-30357 NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion CWE-706 7.3 High 2025-04-18
CVE-2025-30158 NamelessMC Forum iframe width/height abuse causing UI-based Denial of Service CWE-400 7.1 High 2025-04-18
CVE-2025-29784 NamelessMC Has Lack of Length Validation for s Parameter in GET Requests CWE-130 7.5 High 2025-04-18
CVE-2025-22142 Cross-site Scripting in NamelessMC CWE-79 6.1 - 2025-01-13
CVE-2025-22144 Account Takeover in NamelessMC CWE-610 8.1 - 2025-01-13

All 18 known CVE vulnerabilities affecting Nameless with full Chinese analysis, references, and POCs where available.