UI-Based Denial of Service Vulnerability in NamelessMC Forum Software
CVE-2025-30158
7.1HIGH
What is CVE-2025-30158?
In versions 2.1.4 and earlier, NamelessMC's forum software inadvertently permits users to embed iframe elements with unrestricted width and height attributes within forum topics and comments. This allows an authenticated attacker to disrupt normal user interface functionality by injecting oversized iframes, which can block essential UI elements and significantly hinder user interactions. The issue has been resolved in version 2.2.0.
