Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

1234n

First CVE: Mar 27, 2018Active for: 8 yearsTotal CVEs: 35
36.3
VTI Score
Medium

1234n maintains a narrowly focused product portfolio centered on the MiniCMS content-management system, which despite modest volume occupies a notable position among tracked web-application platforms. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the web-facing attack surface inherent to a CMS. The recurring exposure is characterized by application-layer weakness classes including cross-site scripting, cross-site request forgery, improper authentication, and path traversal, which are endemic to web applications handling user input and session management. Defenders deploying or maintaining MiniCMS instances should treat vendor advisories as high-priority and ensure deployment restrictions limit exposure to trusted networks. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 1234n over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2018
8 years ago
Most Recent CVE
Jan 5, 2026
200 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-9092HIGH
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
Mar 27, 20188.839NOYES
CVE-2025-15458CRITICAL
A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manip
Jan 5, 20269.831NONO
CVE-2025-15457CRITICAL
A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handle
Jan 5, 20269.831NONO
CVE-2020-36052CRITICAL
Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.
Jan 5, 20219.831NONO
CVE-2018-18892CRITICAL
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
Nov 1, 20189.830NONO
CVE-2018-1000638MEDIUM
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.
Aug 20, 20186.130NOYES
CVE-2021-33387CRITICAL
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
Feb 24, 20239.628NONO
CVE-2025-15456HIGH
A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. S
Jan 5, 20267.526NONO
CVE-2022-33121HIGH
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
Jun 24, 20228.126NONO
CVE-2020-36051HIGH
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.
Jan 5, 20217.525NONO
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
63%
14%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network35 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (34.3%)
Unknown0 (0.0%)
Required23 (65.7%)
Privileges Required
Low3 (8.6%)
High5 (14.3%)
None27 (77.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 1234n.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 1234n — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 1234n's Products

View all 2 CNAs →

Top CWEs