1234n CVE Vulnerabilities & Metrics

Focus on 1234n vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About 1234n Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with 1234n. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total 1234n CVEs: 28
Earliest CVE date: 27 Mar 2018, 22:29 UTC
Latest CVE date: 31 Oct 2023, 23:15 UTC

Latest CVE reference: CVE-2023-46378

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical 1234n CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.49

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 18
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS 1234n CVEs

These are the five CVEs with the highest CVSS scores for 1234n, sorted by severity first and recency.

All CVEs for 1234n

CVE-2023-46378 1234n vulnerability CVSS: 0 31 Oct 2023, 23:15 UTC

Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.

CVE-2021-33387 1234n vulnerability CVSS: 0 24 Feb 2023, 16:15 UTC

Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.

CVE-2020-19896 1234n vulnerability CVSS: 7.5 28 Jun 2022, 22:15 UTC

File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.

CVE-2022-33121 1234n vulnerability CVSS: 5.8 24 Jun 2022, 21:15 UTC

A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.

CVE-2021-41663 1234n vulnerability CVSS: 4.3 13 Jun 2022, 18:15 UTC

A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.

CVE-2021-44970 1234n vulnerability CVSS: 3.5 10 Feb 2022, 23:15 UTC

MiniCMS v1.11 was discovered to contain a cross-site scripting (XSS) vulnerability via /mc-admin/page-edit.php.

CVE-2020-17999 1234n vulnerability CVSS: 4.3 28 Apr 2021, 16:15 UTC

Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".

CVE-2020-36052 1234n vulnerability CVSS: 7.5 05 Jan 2021, 22:15 UTC

Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

CVE-2020-36051 1234n vulnerability CVSS: 5.0 05 Jan 2021, 22:15 UTC

Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.

CVE-2019-13341 1234n vulnerability CVSS: 3.5 05 Jul 2019, 15:16 UTC

In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.

CVE-2019-13340 1234n vulnerability CVSS: 3.5 05 Jul 2019, 15:16 UTC

In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.

CVE-2019-13339 1234n vulnerability CVSS: 3.5 05 Jul 2019, 15:16 UTC

In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.

CVE-2019-13186 1234n vulnerability CVSS: 4.3 03 Jul 2019, 17:15 UTC

In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.

CVE-2019-9603 1234n vulnerability CVSS: 5.8 06 Mar 2019, 19:29 UTC

MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.

CVE-2018-20520 1234n vulnerability CVSS: 4.3 27 Dec 2018, 15:29 UTC

MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.

CVE-2018-18892 1234n vulnerability CVSS: 7.5 01 Nov 2018, 01:29 UTC

MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.

CVE-2018-18891 1234n vulnerability CVSS: 6.4 01 Nov 2018, 01:29 UTC

MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.

CVE-2018-18890 1234n vulnerability CVSS: 5.0 01 Nov 2018, 01:29 UTC

MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.

CVE-2018-17039 1234n vulnerability CVSS: 4.3 14 Sep 2018, 07:29 UTC

MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.

CVE-2018-16298 1234n vulnerability CVSS: 4.3 31 Aug 2018, 23:29 UTC

An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.

CVE-2018-16233 1234n vulnerability CVSS: 4.3 30 Aug 2018, 22:29 UTC

MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.

CVE-2018-15899 1234n vulnerability CVSS: 4.3 27 Aug 2018, 04:29 UTC

An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

CVE-2018-1000638 1234n vulnerability CVSS: 4.3 20 Aug 2018, 19:31 UTC

MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.

CVE-2018-10424 1234n vulnerability CVSS: 4.0 26 Apr 2018, 05:29 UTC

mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.

CVE-2018-10423 1234n vulnerability CVSS: 4.0 26 Apr 2018, 05:29 UTC

mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.

CVE-2018-10296 1234n vulnerability CVSS: 4.3 22 Apr 2018, 14:29 UTC

MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.

CVE-2018-10227 1234n vulnerability CVSS: 3.5 19 Apr 2018, 08:29 UTC

MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.

CVE-2018-9092 1234n vulnerability CVSS: 6.8 27 Mar 2018, 22:29 UTC

There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.