1234n maintains a narrowly focused product portfolio centered on the MiniCMS content-management system, which despite modest volume occupies a notable position among tracked web-application platforms. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the web-facing attack surface inherent to a CMS. The recurring exposure is characterized by application-layer weakness classes including cross-site scripting, cross-site request forgery, improper authentication, and path traversal, which are endemic to web applications handling user input and session management. Defenders deploying or maintaining MiniCMS instances should treat vendor advisories as high-priority and ensure deployment restrictions limit exposure to trusted networks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 1234n over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9092HIGH There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. | Mar 27, 2018 | 8.8 | 39 | NO | YES |
CVE-2025-15458CRITICAL A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manip | Jan 5, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-15457CRITICAL A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handle | Jan 5, 2026 | 9.8 | 31 | NO | NO |
CVE-2020-36052CRITICAL Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter. | Jan 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-18892CRITICAL MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | Nov 1, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-1000638MEDIUM MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection. | Aug 20, 2018 | 6.1 | 30 | NO | YES |
CVE-2021-33387CRITICAL Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request. | Feb 24, 2023 | 9.6 | 28 | NO | NO |
CVE-2025-15456HIGH A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. S | Jan 5, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-33121HIGH A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link. | Jun 24, 2022 | 8.1 | 26 | NO | NO |
CVE-2020-36051HIGH Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter. | Jan 5, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 1234n.
Media articles that mention a CVE ID that affects a product developed by 1234n — matched by CVE ID, not by vendor name.