Junglewise Threat Intelligence

CVE-2026-32250: NamelessMC reflected XSS in queries user endpoint

CVE-2026-32250 · Severity: medium · CVSS 4.3 · Published 2026-06-02

Technologies: NamelessMC. Vendors: NamelessMC.

Executive brief

NamelessMC, a popular website software for Minecraft servers, contains a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal login sessions, perform phishing, or modify the appearance of the website. This issue affects version 2.2.4 and is resolved in version 2.2.5.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in NamelessMC version 2.2.4 due to improper neutralization of the 'id' parameter in the '/index.php?route=/queries/user/' endpoint. The application reflects user-supplied input directly into the HTML response without adequate sanitization or output encoding. An attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking via cookie theft or DOM manipulation. The vulnerability is fixed in version 2.2.5.

Affected products

  • NamelessMC NamelessMC 2.2.4

Timeline

  • 2026-05-31: advisory: GitHub security advisory published by maintainers
  • 2026-06-02: disclosed: NVD publication date

References

Related threats