Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.57% | — | 1234n Minicms | 5/1/2026 | 30/9/2026 | A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may… | |
| Analizada | Media (5.5) | 0.57% | — | 1234n Minicms | 5/1/2026 | 30/9/2026 | A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.44% | — | 1234n Minicms | 5/1/2026 | 30/9/2026 | A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.69% | — | 1234n Minicms | 5/1/2026 | 30/9/2026 | A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be… | |
| Analizada | Media (6.9) | 0.32% | — | 1234n Minicms | 27/9/2024 | 17/6/2026 | A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (6.9) | 0.36% | — | 1234n Minicms | 27/9/2024 | 17/6/2026 | A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (6.1) | 0.37% | — | 1234n Minicms | 26/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login. | |
| Modificada | Media (5.4) | 0.39% | — | 1234n Minicms | 31/10/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php. | |
| Modificada | Crítica (9.6) | 0.84% | — | 1234n Minicms | 24/2/2023 | 17/6/2026 | Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request. | |
| Modificada | Crítica (9.8) | 1.6% | — | 1234n Minicms | 28/6/2022 | 17/6/2026 | File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php. | |
| Modificada | Alta (8.1) | 0.41% | — | 1234n Minicms | 24/6/2022 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link. | |
| Modificada | Media (6.1) | 0.77% | — | 1234n Minicms | 13/6/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page. | |
| Modificada | Media (5.4) | 0.49% | — | 1234n Minicms | 10/2/2022 | 17/6/2026 | MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php. | |
| Modificada | Media (6.1) | 1.6% | — | 1234n Minicms | 28/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php". | |
| Modificada | Crítica (9.8) | 1.9% | — | 1234n Minicms | 5/1/2021 | 17/6/2026 | Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | 1234n Minicms | 5/1/2021 | 17/6/2026 | Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter. | |
| Modificada | Media (4.8) | 0.62% | — | 1234n Minicms | 5/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. | |
| Modificada | Media (4.8) | 0.62% | — | 1234n Minicms | 5/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186. | |
| Modificada | Media (4.8) | 0.63% | — | 1234n Minicms | 5/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie. | |
| Modificada | Media (6.1) | 0.86% | — | 1234n Minicms | 3/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520. | |
| Modificada | Media (6.5) | 0.51% | — | 1234n Minicms | 6/3/2019 | 17/6/2026 | MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891. | |
| Modificada | Media (6.1) | 0.86% | — | 1234n Minicms | 27/12/2018 | 17/6/2026 | MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233. | |
| Modificada | Crítica (9.8) | 2.6% | — | 1234n Minicms | 1/11/2018 | 17/6/2026 | MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | |
| Modificada | Alta (7.5) | 1.2% | — | 1234n Minicms | 1/11/2018 | 17/6/2026 | MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late. | |
| Modificada | Media (5.3) | 1.5% | — | 1234n Minicms | 1/11/2018 | 17/6/2026 | MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename. |