CVE Database
/

CVE-2026-40571

Back to search

CVE-2026-40571

Published: Jun 2, 2026

Modified: Jun 3, 2026

PUBLISHED

Description

NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private or blocking profile posts. Version 2.2.5 contains a patch.

VendorProductVersions

NamelessMC

Nameless

affected
= 2.2.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now