PT-2026-45800 · Unknown · Namelessmc

·

CVE-2026-35443

·

Published

2026-06-02

·

Updated

2026-06-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NamelessMC version 2.2.4
Description In the modules/Forum/classes/ForumPostReactionContext.php file, the software verifies if a caller can view the forum but fails to enforce the topic-level view other topics authorization. This allows users who are restricted to viewing only their own topics to read and modify reactions on topics belonging to other users.
Recommendations Update to version 2.2.5.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35443
GHSA-WCRF-5GCP-PF64

Affected Products

Namelessmc