CVE-2025-30357
NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion
Description
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator deletes the malicious user's account, all their posts (comments) along with the associated topics (by unrelated users) will be marked as deleted. This issue has been patched in version 2.2.0.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:HPrivileges RequiredUI:RUser InteractionS:CScopeC:NConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Timeline
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-30357 and every CVE in our database. Create a free account — no credit card required.
Create Free Account