Filtered by vendor 1234n
Subscriptions
Total
31 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-9282 | 2 1234n, Bg5sbk | 2 Minicms, Minicms | 2025-08-20 | 4.3 Medium |
A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2024-9281 | 2 1234n, Bg5sbk | 2 Minicms, Minicms | 2025-08-20 | 4.3 Medium |
A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions confusing version and file name information. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2024-31741 | 1 1234n | 1 Minicms | 2025-04-18 | 6.1 Medium |
Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login. | ||||
CVE-2021-33387 | 1 1234n | 1 Minicms | 2025-03-12 | 9.6 Critical |
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request. | ||||
CVE-2023-46378 | 1 1234n | 1 Minicms | 2024-11-21 | 5.4 Medium |
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php. | ||||
CVE-2022-33121 | 1 1234n | 1 Minicms | 2024-11-21 | 8.1 High |
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link. | ||||
CVE-2021-44970 | 1 1234n | 1 Minicms | 2024-11-21 | 5.4 Medium |
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php. | ||||
CVE-2021-41663 | 1 1234n | 1 Minicms | 2024-11-21 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page. | ||||
CVE-2020-36052 | 1 1234n | 1 Minicms | 2024-11-21 | 9.8 Critical |
Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter. | ||||
CVE-2020-36051 | 1 1234n | 1 Minicms | 2024-11-21 | 7.5 High |
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter. | ||||
CVE-2020-19896 | 1 1234n | 1 Minicms | 2024-11-21 | 9.8 Critical |
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php. | ||||
CVE-2020-17999 | 1 1234n | 1 Minicms | 2024-11-21 | 6.1 Medium |
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php". | ||||
CVE-2019-9603 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891. | ||||
CVE-2019-13341 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. | ||||
CVE-2019-13340 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186. | ||||
CVE-2019-13339 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie. | ||||
CVE-2019-13186 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520. | ||||
CVE-2018-9092 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. | ||||
CVE-2018-20520 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233. | ||||
CVE-2018-18892 | 1 1234n | 1 Minicms | 2024-11-21 | N/A |
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. |