Security Advisory

CVE-2026-35443

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-02 15:50:06
Last updated 2026-06-02 18:08:08
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the forum but may only view their own topics, reactions can still be read and modified on other users' topics. Version 2.2.5 fixes the issue.