Technology · Pmmp
Pmmp PocketMine-MP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 34 vulnerabilities in Pmmp PocketMine-MP: 0 in the last 7 days and 32 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86204, was published on 9 September 2026.
- Last 7 days
- 0
- Last 90 days
- 32
- Critical, all time
- 0
- Exploited in the wild
- 0
About Pmmp PocketMine-MP
PocketMine-MP is an open-source server software for Minecraft: Bedrock Edition written in PHP.
Latest Pmmp PocketMine-MP vulnerabilities
- CVE-2026-86204: PocketMine-MP denial of service in ModalFormResponsePacket handlingmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86203: PocketMine-MP item duplication via despawn entity attack race conditionlowCVSS 3.7EPSS 0.4%
- CVE-2026-86202: PocketMine-MP network amplification in ActorEventPacketmediumCVSS 4.3EPSS 0.4%
- CVE-2026-86201: PocketMine-MP denial of service in LoginPacket processinghighCVSS 7.5EPSS 0.6%
- CVE-2026-86200: PocketMine-MP denial of service in LoginPacket handlermediumCVSS 5.3EPSS 0.6%
- CVE-2026-86199: PocketMine-MP certificate validation bypass in offline loginhighCVSS 7.5EPSS 0.5%
- CVE-2026-86198: PocketMine-MP improper validation of ResourcePackClientResponsePacketmediumCVSS 4.2EPSS 0.4%
- CVE-2025-71418: PocketMine-MP denial of service via unlimited explode() in packet parsingmediumCVSS 5.3EPSS 0.4%
- CVE-2025-71417: PocketMine-MP resource pack UUID validation denial of servicemediumCVSS 6.5EPSS 0.3%
- CVE-2024-58381: PocketMine-MP denial of service in LoginPacket JSON processinghighCVSS 7.5EPSS 0.4%
- CVE-2024-58380: PocketMine-MP denial of service in BookEditPacket handlingmediumCVSS 6.5EPSS 0.4%
- CVE-2023-54396: PocketMine-MP dye color ID validation failure in banner deserializationmediumCVSS 6.5EPSS 0.4%
- CVE-2023-54395: PocketMine-MP denial-of-service in ModalFormResponsePacket processingmediumCVSS 4.3EPSS 0.3%
- CVE-2023-54394: PocketMine-MP missing rate-limit for mismatch inventory transactionsmediumCVSS 4.3EPSS 0.4%
- CVE-2023-54393: PocketMine-MP denial of service in LoginPacket JSON parsinghighCVSS 7.5EPSS 0.4%
- CVE-2023-54392: PocketMine-MP NBT tag validation bypass in BlockActorDataPacketmediumCVSS 6.5EPSS 0.4%
- CVE-2023-54390: PocketMine-MP denial of service in LoginPacket JSON parsinghighCVSS 7.5EPSS 0.3%
- CVE-2023-54355: PocketMine-MP EC key validation bypass in LoginPackethighCVSS 7.5EPSS 0.2%
- CVE-2022-51018: PocketMine-MP input validation bypass in book creationmediumCVSS 6.5EPSS 0.4%
- CVE-2022-51017: PocketMine-MP input validation bypass in skin datahighCVSS 7.5EPSS 0.5%
- CVE-2022-51016: PocketMine-MP login replay vulnerability without protocol encryptionmediumCVSS 6.1EPSS 0.2%
- CVE-2022-51015: PocketMine-MP input validation bypass in PlayerActionPacketmediumCVSS 6.5EPSS 0.7%
- CVE-2022-51014: PocketMine-MP unhandled exception in form response handlingmediumCVSS 6.5EPSS 0.5%
- CVE-2022-51013: PocketMine-MP input validation bypass in item damage metadatamediumCVSS 6.5EPSS 0.5%
- CVE-2022-51012: PocketMine-MP NBT deserialization denial of servicemediumCVSS 6.5EPSS 0.5%
Most severe Pmmp PocketMine-MP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-86201: PocketMine-MP denial of service in LoginPacket processinghighCVSS 7.5EPSS 0.6%
- CVE-2026-86199: PocketMine-MP certificate validation bypass in offline loginhighCVSS 7.5EPSS 0.5%
- CVE-2022-51017: PocketMine-MP input validation bypass in skin datahighCVSS 7.5EPSS 0.5%
- CVE-2024-58381: PocketMine-MP denial of service in LoginPacket JSON processinghighCVSS 7.5EPSS 0.4%
- CVE-2023-54393: PocketMine-MP denial of service in LoginPacket JSON parsinghighCVSS 7.5EPSS 0.4%
- CVE-2023-54390: PocketMine-MP denial of service in LoginPacket JSON parsinghighCVSS 7.5EPSS 0.3%
- CVE-2022-51009: PocketMine-MP denial of service in skin geometry JSON parsinghighCVSS 7.5EPSS 0.3%
- CVE-2023-54355: PocketMine-MP EC key validation bypass in LoginPackethighCVSS 7.5EPSS 0.2%
- PocketMine-MP denial of service via junk properties in LoginPacketmediumCVSS 6.9
- CVE-2022-51015: PocketMine-MP input validation bypass in PlayerActionPacketmediumCVSS 6.5EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 5 | 0 | |
| 7 Sep 2026 | 27 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pocketmine-mp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Pmmp PocketMine-MP vulnerabilities", https://junglewise.ai/threats/technologies/pocketmine-mp, 28 September 2026.