CVE-2018-9092: 1234n Minicms

High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.

There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.

Affected products

  • 1234n Minicms: version 1.10 only

Published 2018-03-27. Last modified 2026-06-17.