pmmp has 32 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 32. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-20 (11) and CWE-400 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 32 prev 0
Weakness classes
Products
- PocketMine-MP 32
Worst active — by depth score
CVE-2026-86201High· 7.5PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization53CVE-2026-86199High· 7.5PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication53CVE-2026-86204Medium· 6.5PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service48CVE-2024-58381High· 7.5PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data41CVE-2023-54393High· 7.5PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency41
pmmp vulnerabilities
CVEs affecting pmmp, newest first. Open any entry for full detail, references, and exploit status.
32 CVEsRSS
CVE-2021-48006Low· 3.3PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt
PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored …
CVE-2020-37277Medium· 6.5PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method
PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple confli…