CVE-2018-18891: 1234n Minicms

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.

Affected products

  • 1234n Minicms: version 1.10 only

Published 2018-11-01. Last modified 2026-06-17.