CVE-2018-18890: 1234n Minicms
Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
Affected products
- 1234n Minicms: version 1.10 only
Published 2018-11-01. Last modified 2026-06-17.