PT-2026-45749 · Unknown · Namelessmc

·

CVE-2026-32250

·

Published

2026-06-02

·

Updated

2026-06-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NamelessMC version 2.2.4
Description A Reflected Cross-Site Scripting (XSS) issue exists where the application reflects user-supplied input into the HTML response without proper sanitization or output encoding. This occurs at the endpoint "/index.php?route=/queries/user/" via the id parameter. An attacker can craft a malicious URL containing JavaScript code that executes in the victim's browser, potentially leading to session hijacking, phishing attacks, or manipulation of page content.
Recommendations Update to version 2.2.5. As a temporary workaround, avoid using the id parameter in the "/index.php?route=/queries/user/" endpoint until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32250
GHSA-343F-C4GF-RXC7

Affected Products

Namelessmc