1234nCVEs & Vulnerabilities

35 CVEs affecting 1234n products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

minicms 35
CVE-2025-15458CRITICAL

A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

5 Jan 2026
9.8
CVSS
CVE-2025-15457CRITICAL

A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

5 Jan 2026
9.8
CVSS
CVE-2025-15456HIGH

A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. The vendor was contacted early about this disclosure but did not respond in any way.

5 Jan 2026
7.5
CVSS
CVE-2025-15455MEDIUM

A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5 Jan 2026
6.5
CVSS
CVE-2024-9282MEDIUM

A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.

27 Sep 2024
4.3
CVSS
CVE-2024-9281MEDIUM

A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way.

27 Sep 2024
4.3
CVSS
CVE-2024-31741MEDIUM

Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.

27 Apr 2024
6.1
CVSS
CVE-2023-46378MEDIUM

Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.

1 Nov 2023
5.4
CVSS
CVE-2021-33387CRITICAL

Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.

24 Feb 2023
9.6
CVSS
CVE-2020-19896CRITICAL

File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.

29 Jun 2022
9.8
CVSS
CVE-2022-33121HIGH

A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.

25 Jun 2022
8.1
CVSS
CVE-2021-41663MEDIUM

A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.

13 Jun 2022
6.1
CVSS
CVE-2021-44970MEDIUM

MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.

11 Feb 2022
5.4
CVSS
CVE-2020-17999MEDIUM

Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".

28 Apr 2021
6.1
CVSS
CVE-2020-36052CRITICAL

Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

6 Jan 2021
9.8
CVSS
CVE-2020-36051HIGH

Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.

6 Jan 2021
7.5
CVSS
CVE-2019-13341MEDIUM

In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.

5 Jul 2019
4.8
CVSS
CVE-2019-13340MEDIUM

In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.

5 Jul 2019
4.8
CVSS
CVE-2019-13339MEDIUM

In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.

5 Jul 2019
4.8
CVSS
CVE-2019-13186MEDIUM

In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.

3 Jul 2019
6.1
CVSS
CVE-2019-9603MEDIUM

MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.

6 Mar 2019
6.5
CVSS
CVE-2018-20520MEDIUM

MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.

27 Dec 2018
6.1
CVSS
CVE-2018-18892CRITICAL

MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.

1 Nov 2018
9.8
CVSS
CVE-2018-18891HIGH

MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.

1 Nov 2018
7.5
CVSS
CVE-2018-18890MEDIUM

MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.

1 Nov 2018
5.3
CVSS
CVE-2018-17039MEDIUM

MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.

14 Sep 2018
6.1
CVSS
CVE-2018-16298MEDIUM

An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.

1 Sep 2018
6.1
CVSS
CVE-2018-16233MEDIUM

MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.

31 Aug 2018
6.1
CVSS
CVE-2018-15899MEDIUM

An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

27 Aug 2018
6.1
CVSS
CVE-2018-1000638MEDIUMpoc

MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.

20 Aug 2018
6.1
CVSS
CVE-2018-10424LOW

mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.

26 Apr 2018
2.7
CVSS
CVE-2018-10423LOW

mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.

26 Apr 2018
2.7
CVSS
CVE-2018-10296MEDIUM

MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.

22 Apr 2018
6.1
CVSS
CVE-2018-10227MEDIUM

MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.

19 Apr 2018
5.4
CVSS
CVE-2018-9092HIGHpoc

There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.

28 Mar 2018
8.8
CVSS
← PrevPage 1 / 1Next →