CVE-2020-18693: Mineweb Minewebcms

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.

Affected products

  • Mineweb Minewebcms: version 1.7.0 only

Published 2021-08-06. Last modified 2026-06-17.