CVE-2025-30357

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 18, 2025
Updated: May 13, 2025
CWE ID 706

Summary

CVE-2025-30357 is a vulnerability affecting NamelessMC, a popular website software for Minecraft servers. In versions prior to 2.2.0, if a malicious user leaves spam comments on multiple topics, an administrator, unable to remove each comment manually, may delete the user's account instead. This action results in the deletion of the malicious user's posts and associated topics, potentially causing unintended data loss for legitimate users. This issue can be exploited to disrupt communication and cause confusion within Minecraft server communities. The vulnerability has been resolved in version 2.2.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share