PocketMine-MP vulnerabilities
CVEs whose affected-version data names the PocketMine-MP package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
32 CVEsRSS
CVE-2021-48006Low· 3.3PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt
PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored …
▾ Sunlitpmmp · PocketMine-MPEPSS 0.11%via NVD
CVE-2020-37277Medium· 6.5PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method
PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple confli…
▾ Sunlitpmmp · PocketMine-MPEPSS 0.29%via NVD