CVE-2018-18892: 1234n Minicms

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.

Affected products

  • 1234n Minicms: version 1.10 only

Published 2018-11-01. Last modified 2026-06-17.