Reflected XSS in NamelessMC Website Software for Minecraft Servers
CVE-2026-32250

4.3MEDIUM

Key Information:

Vendor

Namelessmc

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-32250?

A reflected Cross-Site Scripting (XSS) vulnerability exists in NamelessMC, a website software used for Minecraft servers. This vulnerability affects version 2.2.4 and is found in the id parameter of the /index.php?route=/queries/user/ endpoint. The application fails to properly sanitize or encode user inputs from the id parameter, allowing attackers to craft malicious URLs containing JavaScript code. When a victim accesses such a URL, the injected script executes in the victim's browser under the domain of the vulnerable application. This could facilitate session hijacking, phishing schemes, or unauthorized manipulation of webpage content. The issue has been addressed in version 2.2.5.

Affected Version(s)

Nameless = 2.2.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.