Reflected XSS in NamelessMC Website Software for Minecraft Servers
CVE-2026-32250
4.3MEDIUM
What is CVE-2026-32250?
A reflected Cross-Site Scripting (XSS) vulnerability exists in NamelessMC, a website software used for Minecraft servers. This vulnerability affects version 2.2.4 and is found in the id parameter of the /index.php?route=/queries/user/ endpoint. The application fails to properly sanitize or encode user inputs from the id parameter, allowing attackers to craft malicious URLs containing JavaScript code. When a victim accesses such a URL, the injected script executes in the victim's browser under the domain of the vulnerable application. This could facilitate session hijacking, phishing schemes, or unauthorized manipulation of webpage content. The issue has been addressed in version 2.2.5.
Affected Version(s)
Nameless = 2.2.4
