Mineadmin is a niche but notably leveraged game-server management platform whose vulnerabilities skew toward serious outcomes, with an elevated share reaching critical severity. The recurring exposure centers on a single product and clusters around access-control and information-disclosure weaknesses—including improper authorization, privilege-assignment errors, code-injection vectors, and sensitive-data exposure—that are characteristic of web-facing administrative interfaces managing high-value game infrastructure. Defenders should treat this vendor's advisories as urgent for any internet-reachable game-server deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mineadmin over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65854CRITICAL Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover. | Dec 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-1193HIGH A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation le | Jan 19, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-1195HIGH A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insu | Jan 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-1196MEDIUM A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to | Jan 20, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-1194HIGH A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack | Jan 20, 2026 | 7.5 | 22 | NO | NO |
A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the file /system/downloadById. Performing a manipulation of the arg | Jan 20, 2026 | 3.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mineadmin.
Media articles that mention a CVE ID that affects a product developed by Mineadmin — matched by CVE ID, not by vendor name.