CVE-2025-30357

Source
https://cve.org/CVERecord?id=CVE-2025-30357
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30357.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30357
Aliases
  • GHSA-22mc-7c9m-gv8h
Published
2025-04-18T15:51:21.670Z
Modified
2026-04-10T05:24:45.798451Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H CVSS Calculator
Summary
NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion
Details

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator deletes the malicious user's account, all their posts (comments) along with the associated topics (by unrelated users) will be marked as deleted. This issue has been patched in version 2.2.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30357.json",
    "cwe_ids": [
        "CWE-706"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/namelessmc/nameless

Affected ranges

Type
GIT
Repo
https://github.com/namelessmc/nameless
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v2.*
v2.0.0
v2.0.0-pr1
v2.0.0-pr10
v2.0.0-pr11
v2.0.0-pr13
v2.0.0-pr2
v2.0.0-pr3
v2.0.0-pr4
v2.0.0-pr5
v2.0.0-pr6
v2.0.0-pr7
v2.0.0-pr8
v2.0.1
v2.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30357.json"