Insecure View Count Mechanism in NamelessMC Forum Page
CVE-2025-31120
5.3MEDIUM
What is CVE-2025-31120?
NamelessMC, a popular website software for Minecraft servers, has a vulnerability in its forum page code, allowing unauthenticated attackers to artificially inflate view counts. The application utilizes a client-side cookie or session variable to track views, but when these are not provided, it increments the view counter with every page request. This flaw leads to inflated and misleading view metrics, which could impact analytics and user experience. The issue has been addressed and resolved in version 2.2.0 of NamelessMC.
