Vendors1234nminicms1.11
Vulnerabilities

1234n MiniCMS 1.11

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-33121
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
Published 2022-06-24 · Modified
8.1EPSS 0.004
CVE-2021-41663
A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.
Published 2022-06-13 · Modified
6.1EPSS 0.008
CVE-2024-31741
Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.
Published 2024-04-26 · Analyzed
6.1EPSS 0.004
CVE-2021-44970
MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.
Published 2022-02-10 · Modified
5.4EPSS 0.005
CVE-2023-46378
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
Published 2023-10-31 · Modified
5.4EPSS 0.004