📦 Minicms

by 1234n

🔍 What is Minicms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-36052

CRITICAL CVSS 9.8 Jan 5, 2021

This directory traversal vulnerability in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter in post-edit.php. This can lead to remote code execution,...

CVE-2025-15458

HIGH CVSS 7.3 Jan 5, 2026

This vulnerability allows attackers to bypass authentication in MiniCMS versions up to 1.8 by exploiting an unknown function in the article handler component. Attackers can remotely manipulate the sys...

CVE-2025-15457

HIGH CVSS 7.3 Jan 5, 2026

This vulnerability allows remote attackers to bypass authentication in MiniCMS's trash file restore functionality, potentially enabling unauthorized access to administrative features. It affects MiniC...

CVE-2025-15456

HIGH CVSS 7.3 Jan 5, 2026

This vulnerability in MiniCMS allows attackers to bypass authentication mechanisms and potentially publish unauthorized pages. It affects MiniCMS versions up to 1.8. The vulnerability is remotely expl...

CVE-2022-33121

HIGH CVSS 8.1 Jun 24, 2022

This CSRF vulnerability in MiniCMS v1.11 allows attackers to trick authenticated users into clicking malicious links that delete local .dat files. Any MiniCMS v1.11 installation with authenticated use...

CVE-2020-36051

HIGH CVSS 7.5 Jan 5, 2021

This directory traversal vulnerability in MiniCMS V1.10 allows remote attackers to read arbitrary files on the server by manipulating the state parameter in page_edit.php. Any organization running Min...

CVE-2025-15455

MEDIUM CVSS 6.5 Jan 5, 2026

This vulnerability in MiniCMS allows attackers to bypass authentication and delete pages remotely without proper credentials. It affects MiniCMS versions up to 1.8. The exploit is publicly available a...

CVE-2024-9281

MEDIUM CVSS 4.3 Sep 27, 2024

This vulnerability in MiniCMS allows attackers to perform Cross-Site Request Forgery (CSRF) attacks via the post-edit.php file. Attackers can trick authenticated users into performing unintended actio...

CVE-2018-15899

MEDIUM CVSS 6.1 Aug 27, 2018

This is a cross-site scripting (XSS) vulnerability in MiniCMS 1.10 that allows attackers to inject malicious scripts via the 'date' parameter in post.php. This affects any website running the vulnerab...