Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.57%—1234n Minicms5/1/202630/9/2026
A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may…
AnalizadaMedia (5.5)0.57%—1234n Minicms5/1/202630/9/2026
A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made…
AnalizadaMedia (5.5)0.44%—1234n Minicms5/1/202630/9/2026
A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public…
AnalizadaMedia (5.5)0.69%—1234n Minicms5/1/202630/9/2026
A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be…
AnalizadaMedia (6.9)0.32%—1234n Minicms27/9/202417/6/2026
A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (6.9)0.36%—1234n Minicms27/9/202417/6/2026
A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (6.1)0.37%—1234n Minicms26/4/202417/6/2026
Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.
ModificadaMedia (5.4)0.39%—1234n Minicms31/10/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
ModificadaCrítica (9.6)0.84%—1234n Minicms24/2/202317/6/2026
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
ModificadaCrítica (9.8)1.6%—1234n Minicms28/6/202217/6/2026
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
ModificadaAlta (8.1)0.41%—1234n Minicms24/6/202217/6/2026
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
ModificadaMedia (6.1)0.77%—1234n Minicms13/6/20229/7/2026
A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.
ModificadaMedia (5.4)0.49%—1234n Minicms10/2/202217/6/2026
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.
ModificadaMedia (6.1)1.6%—1234n Minicms28/4/202117/6/2026
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
ModificadaCrítica (9.8)1.9%—1234n Minicms5/1/202117/6/2026
Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.
ModificadaAlta (7.5)2.0%—1234n Minicms5/1/202117/6/2026
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.
ModificadaMedia (4.8)0.62%—1234n Minicms5/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
ModificadaMedia (4.8)0.62%—1234n Minicms5/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.
ModificadaMedia (4.8)0.63%—1234n Minicms5/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
ModificadaMedia (6.1)0.86%—1234n Minicms3/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.
ModificadaMedia (6.5)0.51%—1234n Minicms6/3/201917/6/2026
MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
ModificadaMedia (6.1)0.86%—1234n Minicms27/12/201817/6/2026
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.
ModificadaCrítica (9.8)2.6%—1234n Minicms1/11/201817/6/2026
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
ModificadaAlta (7.5)1.2%—1234n Minicms1/11/201817/6/2026
MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
ModificadaMedia (5.3)1.5%—1234n Minicms1/11/201817/6/2026
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.